Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pls Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Pls Kontrola logu

#1 Příspěvek od *AdR!cK* »

Nejak mi zacal mrznut notebook tak pls skontrolujte mi log

Logfile of random's system information tool 1.09 (written by random/random)
Run by PC at 2011-10-26 17:57:16
Microsoft Windows 7 Ultimate
System drive C: has 9 GB (8%) free of 120 GB
Total RAM: 3071 MB (32% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:57:19, on 26. 10. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16839)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\BitTorrent\BitTorrent.exe
C:\Program Files (x86)\Iminent\IMBooster\IMBooster.exe
C:\Windows\update.tray-14-0\svchost.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\TuneUp Utilities 2011\OneClick.exe
C:\Users\PC\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/?appId=54130F ... BF09D0316E
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: IMinent WebBooster - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\IMBooster4Web\Iminent.WebBooster.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMBooster] C:\Program Files (x86)\Iminent\IMBooster\imbooster.exe /warmup
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-14-0\svchost.exe
O4 - HKLM\..\Run: [1179274.exe] "C:\Windows\TEMP\1179274.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [2828025.exe] "C:\Users\PC\AppData\Local\Temp\2828025.exe"
O4 - HKLM\..\Run: [7798636.exe] "C:\Windows\TEMP\7798636.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-4P45N.exe" /REG /REGSVRMODE
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243 (NisSrv) - Unknown owner - C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: wxpdrivers - Cronosoft - C:\Windows\update.1\svchost.exe

--
End of file - 11988 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default

prefs.js - "browser.startup.homepage" - "http://search.iminent.com/?appId=54130F ... BF09D0316E"
prefs.js - "extensions.enabledItems" - "engine@conduit.com:3.2.5.2, {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.2.5.2, plugin@gameplaylabs.com:1.0, toolbar@ask.com:3.12.2.100007, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:3.2.5.2, ffxtlbr@babylon.com:1.1.8, webbooster@iminent.com:4.22.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.21"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =382950&p="

"{6E19037A-12E3-4295-8915-ED48BC341614}"=C:\Program Files (x86)\RelevantKnowledge
"{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}"=C:\Program Files (x86)\RelevantKnowledge


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@protectdisc.com/NPMPDRM]
"Description"=MPDRM License Acquisition Plugin
"Path"=C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448]
"Description"=6.0.12.448
"Path"=C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
webbooster@iminent.com
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files (x86)\Mozilla Firefox\plugins\
npnul32.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
babylon.xml
dunaj-sk.xml
eBay.xml
google.xml
SearchTheWeb.xml
slovnik-sk.xml
wikipedia-sk.xml
yahoo.xml
zoznam-sk.xml

C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\
engine@conduit.com
ffxtlbr@babylon.com
plugin@gameplaylabs.com
toolbar@ask.com
{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}

C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\searchplugins\
conduit.xml
SearchTheWeb.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21A88CB9-84D2-4020-A2D1-B25A21034884}]
HistoryTriggerBHO Class - C:\Program Files (x86)\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll [2011-07-14 35688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll [2011-06-27 270960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
BitTorrentBar Toolbar - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
IMinent WebBooster (BHO) - C:\Program Files (x86)\Iminent\IMBooster4Web\Iminent.WebBooster.dll [2011-03-22 335336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-27 305328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-07-19 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - BitTorrentBar Toolbar - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll [2011-06-27 237168]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-27 305328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMBooster"=C:\Program Files (x86)\Iminent\IMBooster\imbooster.exe [2011-03-30 1324008]
"wxpdrv"=C:\Windows\services32.exe [2011-10-26 1198080]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-14-0\svchost.exe [2011-10-26 1198080]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"1179274.exe"=C:\Windows\TEMP\1179274.exe [2011-10-26 258048]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-10-26 258048]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-10-26 258048]
"2828025.exe"=C:\Users\PC\AppData\Local\Temp\2828025.exe [2011-10-26 258048]
"7798636.exe"=C:\Windows\TEMP\7798636.exe [2011-10-26 1947136]
"systemup"=C:\Windows\systemup.exe [2011-10-26 380416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
"InnoSetupRegFile.0000000001"=C:\Windows\is-4P45N.exe [2011-10-26 709968]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"BitTorrent"=C:\Program Files (x86)\BitTorrent\BitTorrent.exe [2011-04-13 400760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"DisableThumbnails"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"vidc.divx"=divx.dll
"vidc.yv12"=yv12vfw.dll
"vidc.xvid"=xvidvfw.dll
"vidc.ffds"=ff_vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.divxa32"=DivXa32.acm
"msacm.lameacm"=lameACM.acm
"vidc.iv50"=ir50_32.dll
"VIDC.IV41"=IR41_32.AX
"msacm.avis"=ff_acm.acm
"msacm.ac3acm"=ac3acm.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-10-26 17:54:07 ----A---- C:\Windows\systemup.exe
2011-10-26 17:53:32 ----D---- C:\rsit
2011-10-26 17:51:11 ----D---- C:\Program Files (x86)\Trend Micro
2011-10-26 17:50:47 ----A---- C:\Windows\iecheck_iplist.txt
2011-10-26 17:50:20 ----HD---- C:\Windows\update.2
2011-10-26 17:45:08 ----A---- C:\Windows\unrar.exe
2011-10-26 17:40:14 ----A---- C:\Windows\is-4P45N.exe
2011-10-26 17:39:29 ----A---- C:\Windows\iplist.txt
2011-10-26 17:38:06 ----A---- C:\Windows\sysdriver32_.exe
2011-10-26 17:37:52 ----A---- C:\Windows\sysdriver32.exe
2011-10-26 17:37:37 ----D---- C:\Windows\av_ico
2011-10-26 17:37:34 ----A---- C:\Windows\front_ip_list.txt
2011-10-26 17:35:16 ----HD---- C:\Windows\update.1
2011-10-26 17:35:00 ----HD---- C:\Windows\update.tray-14-0-lnk
2011-10-26 17:35:00 ----HD---- C:\Windows\update.tray-14-0
2011-10-26 17:23:46 ----A---- C:\Windows\winlog-ids.txt
2011-10-26 17:23:46 ----A---- C:\Windows\winlog-dirs.txt
2011-10-26 17:23:39 ----A---- C:\Windows\services32.exe
2011-10-25 20:08:53 ----D---- C:\SwSetup
2011-10-01 10:22:59 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2011-10-01 09:22:51 ----A---- C:\RemoteLuaDebuggingServerNetworkConnection.txt
2011-09-29 17:57:11 ----A---- C:\Windows\SysWOW64\uxtuneup.dll
2011-09-29 17:57:09 ----A---- C:\Windows\SysWOW64\authuitu.dll
2011-09-29 17:56:37 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2011-09-22 14:46:39 ----D---- C:\Counter Strike 1.6
2011-09-15 22:16:18 ----D---- C:\Program Files (x86)\Flash Speed 200
2011-09-13 16:34:34 ----D---- C:\ProgramData\IMinent
2011-09-13 16:34:30 ----D---- C:\Program Files (x86)\Iminent
2011-09-09 21:15:04 ----D---- C:\Users\PC\AppData\Roaming\Malwarebytes
2011-09-09 21:14:52 ----A---- C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
2011-09-09 21:14:51 ----D---- C:\ProgramData\Malwarebytes
2011-09-09 21:14:47 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-09 18:28:16 ----D---- C:\ProgramData\GetRight
2011-09-09 18:27:20 ----D---- C:\Users\PC\AppData\Roaming\GetRight
2011-09-08 19:56:20 ----D---- C:\Program Files (x86)\Opera
2011-09-08 14:54:57 ----D---- C:\Program Files (x86)\Common Files\Spigot
2011-09-07 10:17:23 ----D---- C:\Program Files (x86)\LG Electronics
2011-09-06 13:35:34 ----D---- C:\Program Files (x86)\RAR Password Unlocker
2011-09-05 14:25:45 ----D---- C:\Users\PC\AppData\Roaming\IObit
2011-09-05 14:23:32 ----D---- C:\ProgramData\IObit
2011-09-05 14:23:29 ----D---- C:\Program Files (x86)\IObit
2011-09-02 01:10:33 ----D---- C:\Users\PC\AppData\Roaming\GlarySoft
2011-09-02 00:45:25 ----D---- C:\Program Files (x86)\Glary Utilities
2011-09-02 00:41:17 ----D---- C:\Users\PC\AppData\Roaming\Registry Booster
2011-09-02 00:40:47 ----D---- C:\Program Files (x86)\Uniblue
2011-08-31 17:40:18 ----D---- C:\ProgramData\FLEXnet
2011-08-31 17:21:37 ----D---- C:\Program Files (x86)\Bonjour
2011-08-31 17:13:54 ----D---- C:\Windows\SysWOW64\spool
2011-08-31 17:05:32 ----D---- C:\Program Files (x86)\Common Files\Macrovision Shared
2011-08-31 12:51:44 ----RSH---- C:\ProgramData\DEED93B0D0.sys
2011-08-31 12:51:43 ----ASH---- C:\ProgramData\KGyGaAvL.sys
2011-08-29 22:59:15 ----D---- C:\Program Files (x86)\QuickTime
2011-08-29 22:56:38 ----D---- C:\ProgramData\Corel
2011-08-29 22:56:38 ----D---- C:\Program Files (x86)\Common Files\Protexis
2011-08-29 22:52:45 ----D---- C:\Users\PC\AppData\Roaming\Corel
2011-08-29 22:48:46 ----D---- C:\ProgramData\Ulead Systems
2011-08-29 22:48:45 ----D---- C:\Program Files (x86)\Common Files\Corel
2011-08-28 15:19:29 ----D---- C:\Program Files (x86)\Common Files\Steam
2011-08-28 15:19:23 ----D---- C:\Program Files (x86)\Steam
2011-08-28 12:10:20 ----A---- C:\odkazy.txt
2011-08-28 11:34:31 ----D---- C:\Program Files (x86)\CD Recovery Toolbox Free
2011-08-28 10:43:49 ----D---- C:\Users\PC\AppData\Roaming\Media Player Classic
2011-08-28 10:42:16 ----A---- C:\Windows\SysWOW64\yv12vfw.dll
2011-08-28 10:42:08 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2011-08-28 00:02:02 ----D---- C:\Program Files (x86)\Share Rapid Uploader
2011-08-26 14:28:33 ----D---- C:\Program Files (x86)\BabylonToolbar
2011-08-26 14:28:17 ----D---- C:\Users\PC\AppData\Roaming\Babylon
2011-08-26 14:28:17 ----D---- C:\ProgramData\Babylon
2011-08-25 23:29:04 ----D---- C:\ProgramData\Media Center Programs
2011-08-24 08:30:20 ----A---- C:\Windows\SysWOW64\tzres.dll
2011-08-22 14:02:37 ----D---- C:\Users\PC\AppData\Roaming\Touchstone
2011-08-22 12:41:59 ----D---- C:\Windows\A5B5A16D277A476B8F621029A2F23072.TMP
2011-08-22 12:37:31 ----A---- C:\Windows\disney.ini
2011-08-18 13:27:11 ----D---- C:\Users\PC\AppData\Roaming\Win7codecs
2011-08-18 13:26:52 ----D---- C:\Program Files (x86)\Win7codecs
2011-08-18 13:25:33 ----D---- C:\ProgramData\Win7codecs
2011-08-17 18:45:02 ----D---- C:\Users\PC\AppData\Roaming\TuneUp Software
2011-08-17 18:44:15 ----D---- C:\ProgramData\TuneUp Software
2011-08-17 18:44:06 ----SHD---- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-08-11 07:39:43 ----A---- C:\Windows\SysWOW64\xmllite.dll
2011-08-11 07:39:30 ----A---- C:\Windows\SysWOW64\odbcjt32.dll
2011-08-11 07:39:29 ----A---- C:\Windows\SysWOW64\odbccr32.dll
2011-08-11 07:39:29 ----A---- C:\Windows\SysWOW64\odbccp32.dll
2011-08-11 07:39:28 ----A---- C:\Windows\SysWOW64\odbctrac.dll
2011-08-11 07:39:28 ----A---- C:\Windows\SysWOW64\odbccu32.dll
2011-08-11 07:37:38 ----A---- C:\Windows\SysWOW64\setup16.exe
2011-08-11 07:37:36 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2011-08-11 07:37:34 ----A---- C:\Windows\SysWOW64\wow32.dll
2011-08-11 07:37:34 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2011-08-11 07:37:34 ----A---- C:\Windows\SysWOW64\kernel32.dll
2011-08-11 07:37:31 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-11 07:37:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-11 07:37:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-11 07:37:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-11 07:37:27 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-11 07:37:26 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-11 07:37:26 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-11 07:37:26 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-11 07:37:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-11 07:37:25 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-11 07:37:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-11 07:37:24 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-11 07:37:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-11 07:37:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-11 07:37:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-11 07:37:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-11 07:37:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-11 07:37:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-11 07:37:18 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-11 07:37:18 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-11 07:37:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-11 07:37:11 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-11 07:37:11 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-11 07:37:09 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-11 07:37:09 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-11 07:37:08 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-11 07:37:05 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-11 07:37:04 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-11 07:37:01 ----A---- C:\Windows\SysWOW64\instnm.exe
2011-08-11 07:37:00 ----A---- C:\Windows\SysWOW64\user.exe
2011-08-11 07:35:43 ----A---- C:\Windows\SysWOW64\iertutil.dll
2011-08-11 07:35:41 ----A---- C:\Windows\SysWOW64\ieframe.dll
2011-08-11 07:35:36 ----A---- C:\Windows\SysWOW64\mshtml.dll
2011-08-11 07:35:31 ----A---- C:\Windows\SysWOW64\urlmon.dll
2011-08-11 07:35:27 ----A---- C:\Windows\SysWOW64\wininet.dll
2011-08-11 07:35:27 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2011-08-11 07:35:24 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2011-08-11 07:35:24 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2011-08-11 07:35:23 ----A---- C:\Windows\SysWOW64\mstime.dll
2011-08-11 07:35:21 ----A---- C:\Windows\SysWOW64\url.dll
2011-08-11 07:35:21 ----A---- C:\Windows\SysWOW64\ieui.dll
2011-08-11 07:35:21 ----A---- C:\Windows\SysWOW64\iepeers.dll
2011-08-11 07:35:20 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2011-08-11 07:35:18 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2011-08-11 07:35:18 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2011-08-11 07:35:17 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2011-08-11 07:35:05 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2011-08-11 07:35:03 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2011-08-07 13:24:30 ----D---- C:\Users\PC\AppData\Roaming\PhotoFiltre
2011-08-07 13:24:17 ----D---- C:\Program Files (x86)\PhotoFiltre
2011-08-02 09:14:19 ----D---- C:\Program Files (x86)\AGEIA Technologies
2011-08-01 22:03:50 ----D---- C:\Windows\6833245EDD86479A882A8360D62C8194.TMP
2011-08-01 14:16:11 ----D---- C:\Users\PC\AppData\Roaming\DivX
2011-07-29 13:39:55 ----A---- C:\Windows\SysWOW64\CmdLineExt_x64.dll
2011-07-29 13:35:24 ----A---- C:\Windows\SysWOW64\pbsvc.exe
2011-07-27 11:32:39 ----D---- C:\Program Files (x86)\7-Zip
2011-07-27 01:44:18 ----A---- C:\Windows\SysWOW64\mkl_blueripple.dll
2011-07-27 01:44:08 ----RA---- C:\Windows\SysWOW64\tmp2781.tmp

======List of files/folders modified in the last 3 months======

2011-10-26 17:56:50 ----D---- C:\Users\PC\AppData\Roaming\BitTorrent
2011-10-26 17:54:09 ----D---- C:\Windows\Temp
2011-10-26 17:54:07 ----D---- C:\Windows
2011-10-26 17:51:16 ----SHD---- C:\Windows\Installer
2011-10-26 17:51:11 ----SHD---- C:\Config.Msi
2011-10-26 17:51:11 ----RD---- C:\Program Files (x86)
2011-10-26 17:51:05 ----SHD---- C:\System Volume Information
2011-10-25 23:24:27 ----D---- C:\Windows\System32
2011-10-25 23:24:27 ----D---- C:\Windows\inf
2011-10-25 20:32:34 ----D---- C:\Program Files (x86)\AmIcoSingLun
2011-10-25 20:32:33 ----HD---- C:\ProgramData
2011-10-24 18:55:16 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-10-18 15:22:42 ----D---- C:\Users\PC\AppData\Roaming\DAEMON Tools Lite
2011-10-09 13:51:28 ----D---- C:\Windows\Logs
2011-10-01 10:22:57 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-10-01 10:22:55 ----D---- C:\Windows\SysWOW64
2011-09-29 21:59:14 ----RSD---- C:\Windows\assembly
2011-09-22 13:17:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-09-19 13:55:53 ----SD---- C:\Users\PC\AppData\Roaming\Microsoft
2011-09-18 20:26:10 ----D---- C:\Windows\SoftwareDistribution
2011-09-15 22:24:36 ----RD---- C:\Program Files
2011-09-10 00:55:29 ----D---- C:\Windows\Microsoft.NET
2011-09-09 21:14:53 ----D---- C:\Windows\SysWOW64\drivers
2011-09-09 21:11:11 ----D---- C:\Program Files (x86)\Common Files
2011-09-09 20:45:32 ----D---- C:\Windows\winsxs
2011-09-09 20:41:51 ----D---- C:\Windows\ehome
2011-09-09 20:41:51 ----D---- C:\Program Files (x86)\Windows Media Player
2011-09-09 20:41:49 ----D---- C:\Windows\PolicyDefinitions
2011-09-08 22:17:45 ----D---- C:\Users\PC\AppData\Roaming\Adobe
2011-09-08 19:56:36 ----D---- C:\Users\PC\AppData\Roaming\Opera
2011-09-06 14:09:13 ----D---- C:\Windows\Tasks
2011-09-05 21:12:45 ----D---- C:\Users\PC\AppData\Roaming\vlc
2011-09-05 18:45:09 ----RSD---- C:\Windows\Fonts
2011-09-05 15:54:53 ----D---- C:\Program Files (x86)\Windows Mail
2011-09-05 15:54:45 ----D---- C:\Windows\SysWOW64\xlive
2011-09-05 15:54:31 ----D---- C:\Windows\SysWOW64\C2MP
2011-09-05 15:54:29 ----D---- C:\Windows\system
2011-09-05 15:53:37 ----D---- C:\Windows\IME
2011-09-05 15:53:37 ----D---- C:\Windows\Glass
2011-09-05 15:53:37 ----D---- C:\Windows\Freecorder
2011-09-05 15:53:37 ----D---- C:\Windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP
2011-09-05 15:53:37 ----D---- C:\Windows\E10DB5DAE57640EAA7FC1CB2A7B283A6.TMP
2011-09-05 15:53:36 ----D---- C:\Windows\B83FC356B7C0441F8A4DD71E088E7974.TMP
2011-09-05 15:52:51 ----D---- C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP
2011-09-05 15:52:51 ----D---- C:\Windows\74224F8D4A1748169EDB7BB854DE532C.TMP
2011-09-05 15:52:51 ----D---- C:\Windows\45235788142C44BE8A4DDDE9A84492E5.TMP
2011-09-05 15:52:51 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-09-05 15:52:45 ----D---- C:\Users\PC\AppData\Roaming\ProtectDISC
2011-09-05 15:52:41 ----D---- C:\ProgramData\mpDRM
2011-09-05 15:52:13 ----D---- C:\Program Files (x86)\Winamp
2011-09-05 15:52:11 ----D---- C:\Program Files (x86)\Winamp Detect
2011-09-05 15:51:56 ----D---- C:\Program Files (x86)\The KMPlayer
2011-09-05 15:51:50 ----D---- C:\Program Files (x86)\PCSX2 0.9.8
2011-09-05 15:51:49 ----D---- C:\Program Files (x86)\OpenAL
2011-09-05 15:51:24 ----D---- C:\Program Files (x86)\MP3 WAV WMA Converter
2011-09-05 15:51:22 ----D---- C:\Program Files (x86)\Microsoft Works
2011-09-05 15:51:21 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-09-05 15:50:58 ----D---- C:\Program Files (x86)\MagicISO
2011-09-05 15:50:50 ----D---- C:\Program Files (x86)\FreeImageConverter
2011-09-05 15:50:50 ----D---- C:\Program Files (x86)\Freecorder
2011-09-05 15:50:50 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-09-05 15:50:49 ----D---- C:\Program Files (x86)\ConduitEngine
2011-09-05 15:50:48 ----D---- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-09-05 15:50:47 ----D---- C:\Program Files (x86)\Common Files\mpDRM
2011-09-05 15:50:41 ----D---- C:\Program Files (x86)\Common Files\DESIGNER
2011-09-05 15:50:38 ----D---- C:\Program Files (x86)\Codec Pack - All In 1
2011-09-05 15:50:38 ----D---- C:\Program Files (x86)\BRS
2011-09-05 15:50:38 ----D---- C:\Program Files (x86)\BitTorrentBar
2011-09-05 15:50:38 ----D---- C:\Program Files (x86)\BitTorrent
2011-09-05 15:50:29 ----D---- C:\Program Files (x86)\Ask.com
2011-09-05 15:50:28 ----D---- C:\Program Files (x86)\Apple Software Update
2011-09-05 15:50:23 ----D---- C:\31541ca22f0277a2c4c2
2011-09-05 15:48:28 ----D---- C:\Windows\registration
2011-08-31 17:23:53 ----D---- C:\Program Files (x86)\Common Files\Adobe
2011-08-31 17:22:59 ----D---- C:\ProgramData\Adobe
2011-08-31 17:18:52 ----D---- C:\Program Files (x86)\Adobe
2011-08-29 22:59:55 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-29 22:59:24 ----D---- C:\Program Files (x86)\Common Files\Apple
2011-08-25 01:40:27 ----D---- C:\Windows\SysWOW64\sk-SK
2011-08-23 01:15:49 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-08-23 01:15:15 ----A---- C:\Windows\SysWOW64\PerfStringBackup.INI
2011-08-17 18:52:52 ----D---- C:\Windows\debug
2011-08-17 18:51:06 ----SHD---- C:\$Recycle.Bin
2011-08-17 18:43:00 ----D---- C:\Program Files (x86)\VS Revo Group
2011-08-12 08:02:48 ----D---- C:\Windows\SysWOW64\migration
2011-08-12 08:02:48 ----D---- C:\Windows\AppPatch
2011-08-12 00:27:29 ----A---- C:\Windows\win.ini
2011-08-08 10:00:00 ----A---- C:\Windows\SysWOW64\ff_vfw.dll
2011-08-01 21:59:05 ----D---- C:\Program Files (x86)\AMD
2011-07-29 13:35:36 ----A---- C:\Windows\SysWOW64\PnkBstrB.exe
2011-07-27 19:07:38 ----D---- C:\ProgramData\Codemasters
2011-07-27 01:44:09 ----A---- C:\Windows\SysWOW64\OpenAL32.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys []
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys []
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys []
R3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys []
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys []
R3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys []
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-07-07 11856]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys []
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
R4 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys []
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS []
S3 aryu8u1w;aryu8u1w; C:\Windows\SysWOW64\drivers\aryu8u1w.sys []
S3 ay2h2xu2;ay2h2xu2; C:\Windows\SysWOW64\drivers\ay2h2xu2.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys []
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys []
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys []
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys []
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys []
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgx64bus.sys []
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgx64diag.sys []
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgx64modem.sys []
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2011-07-29 107832]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-10-26 1947136]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-10-26 258048]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-09-27 2027840]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-10-26 1198080]
R4 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 135664]
S2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-08-31 654848]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 135664]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-19 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe []
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-08-28 411432]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------
Naposledy upravil(a) vyosek dne 26 říj 2011 17:14, celkem upraveno 1 x.
Důvod: Log odstranen z code

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Mohu mit dotaz, proc si bezny uzivatel kupuje nejvyssi licenci Windows, ktera je urcena spise pro velke korporace, kdyz stejne nevyuzije nic vic nez nabizi verze Home Premium :???:

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#3 Příspěvek od *AdR!cK* »

Prvy log
RogueKiller V6.1.4 [10/22/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: PC [Admin rights]
Mode: Remove -- Date : 10/26/2011 18:36:01

Bad processes: 3
[SERVICE] wxpdrivers -- C:\Windows\update.1\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- C:\Windows\sysdriver32.exe srv -> STOPPED
[SERVICE] srviecheck -- C:\Windows\update.2\svchost.exe srv -> STOPPED

Registry Entries: 9
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\Windows\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\Windows\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\Windows\update.1\svchost.exe srv) -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED ()
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED ()

Particular Files / Folders:

Driver: [NOT LOADED]

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 http://www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Finished : << RKreport[1].txt >>
RKreport[1].txt



Log 2

RogueKiller V6.1.4 [10/22/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: PC [Admin rights]
Mode: HOSTSFix -- Date : 10/26/2011 18:37:40

Bad processes: 0

Driver: [NOT LOADED]

HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

Log 3

RogueKiller V6.1.4 [10/22/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: PC [Admin rights]
Mode: ProxyFix -- Date : 10/26/2011 18:38:21

Bad processes: 0

Driver: [NOT LOADED]

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#4 Příspěvek od vyosek »

vyosek píše: :arrow: Mohu mit dotaz, proc si bezny uzivatel kupuje nejvyssi licenci Windows, ktera je urcena spise pro velke korporace, kdyz stejne nevyuzije nic vic nez nabizi verze Home Premium :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#5 Příspěvek od *AdR!cK* »

vyosek píše:
vyosek píše: :arrow: Mohu mit dotaz, proc si bezny uzivatel kupuje nejvyssi licenci Windows, ktera je urcena spise pro velke korporace, kdyz stejne nevyuzije nic vic nez nabizi verze Home Premium :???:
To mi rodicia kupili notebook a aj ten windows, a teraz mozme sa venovat tym logom?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#6 Příspěvek od vyosek »

Ale ale, ntb se bezne prodavaji s verzi Home Premium :?: Nac by tam cpali verzi za nekolik tisic a cca 3x tolik co Home premium :?: Takze jak to je :???:

Rad pomuzu, ale blba ze sebe nenecham delat :James008:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#7 Příspěvek od *AdR!cK* »

vyosek píše:Ale ale, ntb se bezne prodavaji s verzi Home Premium :?: Nac by tam cpali verzi za nekolik tisic a cca 3x tolik co Home premium :?: Takze jak to je :???:

Rad pomuzu, ale blba ze sebe nenecham delat :James008:
Tak ja nevim jak to je presne s tym windowsom, som to tak dostal.... a keby si bol tak dobry pls skontroluj mi ten log

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#8 Příspěvek od vyosek »

:arrow: Zaznam o podezreni na nelegal OS pridavam k vasemu nicku do interni sekce, pro pripady do budoucna...

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#9 Příspěvek od *AdR!cK* »

ComboFix 11-10-26.06 - PC . 10. 2011 19:11:53.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.3071.760 [GMT 2:00]
Running from: c:\users\PC\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\PC\AppData\Local\Temp\rad02267.tmp\bin\Gadget.Interop.dll
c:\users\PC\AppData\Local\Temp\radBEB92.tmp\bin\x64\sharpwrapi_x64.dll
c:\users\PC\rkill.com
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\isRS-000.tmp
c:\windows\iun6002.exe
c:\windows\loader2.exe_ok
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\proc_list1.log
c:\windows\system32\ReadMe.txt
c:\windows\SysWow64\ReadMe.txt
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Files Created from 2011-09-26 to 2011-10-26 )))))))))))))))))))))))))))))))
.
.
2011-10-26 17:23 . 2011-10-26 17:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-26 16:35 . 2011-10-26 16:35 719360 ----a-w- C:\RogueKiller.exe
2011-10-26 15:53 . 2011-10-26 15:53 -------- d-----w- C:\rsit
2011-10-26 15:51 . 2011-10-26 15:57 -------- d-----w- c:\program files (x86)\Trend Micro
2011-10-26 15:51 . 2011-10-26 15:51 388096 ----a-r- c:\users\PC\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-26 15:45 . 2011-10-26 15:45 246272 ----a-w- c:\windows\unrar.exe
2011-10-26 15:37 . 2011-10-26 15:37 -------- d-----w- c:\windows\av_ico
2011-10-26 15:35 . 2011-10-26 16:46 -------- d--h--w- c:\windows\update.tray-14-0
2011-10-26 15:35 . 2011-10-26 15:35 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-10-25 18:08 . 2011-10-25 18:08 -------- d-----w- C:\SwSetup
2011-10-24 16:52 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{43C0D88E-D3E3-439F-B3D8-90760D09BDAD}\mpengine.dll
2011-10-16 06:58 . 2011-10-04 15:22 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6B538430-4CFF-477E-BA02-5A7C83123BDA}\gapaengine.dll
2011-10-01 08:22 . 2011-10-01 08:22 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-09-29 19:37 . 2011-09-29 19:37 -------- d--h--w- c:\users\PC\InstallAnywhere
2011-09-29 15:57 . 2011-09-27 11:53 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-09-29 15:57 . 2011-09-27 11:47 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-09-29 15:57 . 2011-09-27 11:46 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-09-29 15:57 . 2011-09-27 11:46 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-09-29 15:57 . 2011-09-27 11:46 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-09-29 15:56 . 2011-09-29 15:57 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-30 19:30 . 2011-08-31 10:51 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2011-09-30 19:30 . 2011-08-31 10:51 88 --sh--r- c:\programdata\DEED93B0D0.sys
2011-09-13 00:26 . 2011-02-21 10:24 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-31 15:00 . 2011-09-09 19:14 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-12 04:10 . 2011-08-22 23:14 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-08 10:41 . 2011-06-20 13:53 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-08 08:00 . 2010-02-14 13:47 74752 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2011-07-29 11:39 . 2011-07-29 11:39 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2011-07-29 11:35 . 2011-03-16 21:26 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-29 11:35 . 2011-07-29 11:35 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-12-09 11:51 3911776 ----a-w- c:\program files (x86)\BitTorrentBar\tbBitT.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 11:29 1490312 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files (x86)\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2011-04-13 400760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMBooster"="c:\program files (x86)\Iminent\IMBooster\imbooster.exe" [2011-03-30 1324008]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableThumbnails"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 135664]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 135664]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-09-27 2027840]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-07-07 11856]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-09-01 07:26]
.
2011-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 15:21]
.
2011-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-02-19 15:21]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.iminent.com/?appId=54130F64-9776-435A-A8B1-11BF09D0316E
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 173.193.227.124 173.192.105.217
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - SearchTheWeb
FF - prefs.js: browser.startup.homepage - hxxp://search.iminent.com/?appId=54130F64-9776-435A-A8B1-11BF09D0316E
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=382950&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Iminent WebBooster: webbooster@iminent.com - c:\program files (x86)\Mozilla Firefox\extensions\webbooster@iminent.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico1 - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-MSC - c:\program files\Microsoft Security Client\msseces.exe
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\FlashUtil10e_plugin.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\FlashUtil10e_plugin.exe
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-10-26 19:40:28
ComboFix-quarantined-files.txt 2011-10-26 17:40
.
Pre-Run: 8 618 553 344 bytes free
Post-Run: 8 965 550 080 bytes free
.
- - End Of File - - B42A9A69DEE927DD1DFC16A72AD8295A

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#10 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\windows\av_ico
    c:\windows\update.tray-14-0
    c:\windows\update.tray-14-0-lnk
    c:\program files (x86)\BitTorrentBar
    c:\program files (x86)\Ask.com
    C:\Program Files (x86)\BabylonToolbar
    
    File::
    c:\windows\unrar.exe
    C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
    [-HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BitTorrent"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes' Anti-Malware (reboot)"=-
    "Malwarebytes' Anti-Malware"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    
    Driver::
    gupdate
    gupdatem
    
    DDS::
    uStart Page = hxxp://search.iminent.com/?appId=54130F ... BF09D0316E
    
    Firefox::
    FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
    FF - prefs.js: browser.search.selectedEngine - SearchTheWeb
    FF - prefs.js: browser.startup.homepage - hxxp://search.iminent.com/?appId=54130F ... BF09D0316E
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=green ... =382950&p=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
    FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
    FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
    FF - Ext: PandoraTV Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
    FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
    FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#11 Příspěvek od *AdR!cK* »

ComboFix 11-10-26.06 - PC . 10. 2011 21:16:15.2.2 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.421.1051.18.3071.1897 [GMT 2:00]
Running from: c:\users\PC\Desktop\ComboFix.exe
Command switches used :: c:\users\PC\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\assets\oobe\b.png
c:\program files (x86)\Ask.com\assets\oobe\bl.png
c:\program files (x86)\Ask.com\assets\oobe\br.png
c:\program files (x86)\Ask.com\assets\oobe\l.png
c:\program files (x86)\Ask.com\assets\oobe\pointer.png
c:\program files (x86)\Ask.com\assets\oobe\r.png
c:\program files (x86)\Ask.com\assets\oobe\t.png
c:\program files (x86)\Ask.com\assets\oobe\tl.png
c:\program files (x86)\Ask.com\assets\oobe\tr.png
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_b5b1.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\precache.exe
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\Updater\config.xml
c:\program files (x86)\Ask.com\Updater\Updater.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\BabylonToolbar
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarApp.dll
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarEng.dll
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarsrv.exe
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\uninstall.exe
c:\program files (x86)\BitTorrentBar
c:\program files (x86)\BitTorrentBar\BitTorrentBarToolbarHelper.exe
c:\program files (x86)\BitTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\INSTALL.LOG
c:\program files (x86)\BitTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\BitTorrentBar\tbBitT.dll
c:\program files (x86)\BitTorrentBar\toolbar.cfg
c:\program files (x86)\BitTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\BitTorrentBar\UNWISE.EXE
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.png
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdf
c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\preview.png
c:\users\PC\AppData\Local\Temp\radCDCDD.tmp\bin\Gadget.Interop.dll
c:\users\PC\AppData\Local\Temp\radCDCDD.tmp\bin\x64\sharpwrapi_x64.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\ConduitAutoCompleteSearch.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\ConduitAutoCompleteSearch.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\ConduitToolbar.idl
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\ConduitToolbar.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\ConduitToolbar.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCore.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCore.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCoreGecko19.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\alertSettingsComponent.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\appContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\engineContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\engineSettings.json
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\fbAlert.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\getAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\postAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\toolbarContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\defaults\unsharedAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\chrome\bittorrentbar.jar
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\lib\xpcom.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\META-INF\manifest.mf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\META-INF\zigbert.rsa
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\META-INF\zigbert.sf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\searchplugin\conduit.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\searchplugin\conduit.ico
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\searchplugin\conduit.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\searchplugin\conduit.src
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\searchplugin\conduit.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\setup.ini
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\version.txt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitAutoCompleteSearch.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.idl
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\ConduitToolbar.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCore.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\components\RadioWMPCoreGecko19.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\alertSettingsComponent.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\appContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\engineSettings.json
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\fbAlert.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\getAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\postAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\toolbarContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\defaults\unsharedAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\chrome\bs_player.jar
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\lib\xpcom.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\manifest.mf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.rsa
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\META-INF\zigbert.sf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.ico
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.src
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\searchplugin\conduit.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\setup.ini
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}\version.txt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\ConduitToolbar.idl
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\ConduitToolbar.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\ConduitToolbar.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\RadioWMPCore.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\appContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\engineContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\engineSettings.json
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\fbAlert.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\DualPackage\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\chrome\conduitengine.jar
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\lib\xpcom.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\META-INF\manifest.mf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\META-INF\zigbert.rsa
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\META-INF\zigbert.sf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\searchplugin\conduit.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\searchplugin\conduit.ico
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\searchplugin\conduit.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\searchplugin\conduit.src
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\searchplugin\conduit.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\setup.ini
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\engine@conduit.com\version.txt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\components\FFHst.dll
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\components\FFHst.xpt
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\babylon.css
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\babylon.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\bbylnDef.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\btnInf.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\09.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\buy.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\games.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\greenCard.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\icons.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\languages.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\lottery.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mj.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\bg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\chooseStation.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\lines.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\pauseBtn.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\playBtn.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\rd_strp.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio\Thumbs.db
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\radio.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\search.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\stat.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbar_icons_games.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\toolbarIcons_casino.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\translate.PNG
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\mtrprt.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\mtstart.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\rd.htm
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\server.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\tmplt.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\content\vssver.scc
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\vssver.scc
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\ffxtlbr@babylon.com\vssver.scc
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\defaults\preferences\prefs.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\chrome\content\ff-overlay.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\chrome\content\icon.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\chrome\content\overlay.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\chrome\locale\en-US\overlay.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\plugin@gameplaylabs.com\setup.ini
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\datastore\cache.sqlite
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\defaults.js.bak
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\defaults\preferences\defaults.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\defaults\preferences\defaults.js.bak
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome.manifest
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\about.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\about.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\bindings.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\button-bindings.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\cache.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\constants.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\core.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\custom-command-listener.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\dynamic-button-manager.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\dynamic-button.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\events.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\feeds.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\http-headers.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\json.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\lifecycle.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\listeners.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\locale.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\logger.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\network.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\newtab-manager.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\newtab-overlay.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\newtab.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\newtab.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\notification-popup-controller.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\notification-popup-ff3.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\notification-popup.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\notification.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\observer.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\options.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\options.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\preferences.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\prefetch.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\ss-popup-bindings.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\suggestions.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\update.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\updateRdf.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\utilities.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\webframe-bindings.xml
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\webframe-manager.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\widget-controller.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\widget-popup.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\content\widgets.js
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\abc.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\amazon_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\as.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ask_16x16.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ask_32x32.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ask_browser_ff_chrome.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ask_kmp1.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ask_mail.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\asklogo.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\b-p.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\b.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bbc_news.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\beppe_grillo.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bild.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bl-pbl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bl-pbr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\bl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\blogs.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\br-pbl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\br-pbr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\br.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\business.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\businessRU.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\celebrity.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\close.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\cnn_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\corriere_della_sera.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\dictionary.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\el_mundo.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\email_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\expansion.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\facebook_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\film1.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\folha.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ft.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ftd.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\g1.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\games_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\gazzetta_dello_sport.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\globe_18x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\gripper.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\highlighter_off.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\highlighter_on.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\history.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\hola.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\chevron.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\images.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\kicker.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\l.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-de.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-en.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-es.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-fr.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-it.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-nl.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-pt.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\labels-ru.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\laposte.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\lemonde.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\lequipe.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\libero_it.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-BR.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-DE.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-ES.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-EU.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-FR.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-IT.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-NL.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-RU.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-UK.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\links-US.properties
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\logo_32x32.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\magnify_search.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\maps.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\mtv.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\news.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\newsNL.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\newsRU.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\newtab.css
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\newtab_bkg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\newtab_search_bkg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\notification.css
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\oglobo.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\orkut.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\personas.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\preferences.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\ptv2_new.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\r.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\radiodigital.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_de.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_es.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_fr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_it.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_nl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pt.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ask_ru.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_cobrand.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_current_site.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_de.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_es.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_fr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_grey_73x24.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_it.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_nl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_pl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_pt.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\search_ru.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\shopping.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\sports.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\sportsNL.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\sportsRU.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\stocks.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\t-p.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\t.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\terra.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\titlebar_bg.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tl-ptl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tl-ptr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\toolbar.css
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\toolbar.xul
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tr-ptl.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tr-ptr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tr.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tv.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\tv_movie_de.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\uol.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\vk.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\voici_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\weather.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\web.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\wordoftheday_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\youtube_16x.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\skin\zoomall.png
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Mon-02-May-2011-15-37-28-GMT\ff-config.zip
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Sun-31-Jul-2011-18-41-02-GMT\ff-config.zip
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Thu-06-Oct-2011-13-57-26-GMT\ff-config.zip
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Tue-06-Sep-2011-19-41-12-GMT\ff-config.zip
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Wed-13-Apr-2011-17-24-20-GMT\ff-config.zip
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\install.rdf
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1302715458968.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1302715470697.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1303639169146.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1304350648266.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1304350660741.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1309183512971.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1312137661459.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1312137680435.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1313040411932.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1313064450431.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1313073472424.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1313135850558.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1314441025357.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1314441384061.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1314652733482.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1314803192740.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1315338070925.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1315394731379.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1315394731958.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1315394732283.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1315595192862.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1317909445605.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1319203137245.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1319475332353.html
c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\extensions\toolbar@ask.com\logs\asktb-log-1319648086204.html
c:\windows\av_ico
c:\windows\av_ico\ico_Essentials_start.ico
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\unrar.exe
c:\windows\update.tray-14-0-lnk
c:\windows\update.tray-14-0-lnk\svchost.exe
c:\windows\update.tray-14-0
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2011-09-26 to 2011-10-26 )))))))))))))))))))))))))))))))
.
.
2011-10-26 16:35 . 2011-10-26 16:35 719360 ----a-w- C:\RogueKiller.exe
2011-10-26 15:53 . 2011-10-26 15:53 -------- d-----w- C:\rsit
2011-10-26 15:51 . 2011-10-26 15:57 -------- d-----w- c:\program files (x86)\Trend Micro
2011-10-26 15:51 . 2011-10-26 15:51 388096 ----a-r- c:\users\PC\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-25 18:08 . 2011-10-25 18:08 -------- d-----w- C:\SwSetup
2011-10-24 16:52 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{43C0D88E-D3E3-439F-B3D8-90760D09BDAD}\mpengine.dll
2011-10-16 06:58 . 2011-10-04 15:22 917840 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6B538430-4CFF-477E-BA02-5A7C83123BDA}\gapaengine.dll
2011-10-01 08:22 . 2011-10-01 08:22 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2011-09-29 19:37 . 2011-09-29 19:37 -------- d--h--w- c:\users\PC\InstallAnywhere
2011-09-29 15:57 . 2011-09-27 11:53 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-09-29 15:57 . 2011-09-27 11:47 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-09-29 15:57 . 2011-09-27 11:46 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-09-29 15:57 . 2011-09-27 11:46 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-09-29 15:57 . 2011-09-27 11:46 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-09-29 15:56 . 2011-09-29 15:57 -------- d-----w- c:\program files (x86)\TuneUp Utilities 2011
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-30 19:30 . 2011-08-31 10:51 2828 --sha-w- c:\programdata\KGyGaAvL.sys
2011-09-30 19:30 . 2011-08-31 10:51 88 --sh--r- c:\programdata\DEED93B0D0.sys
2011-09-13 00:26 . 2011-02-21 10:24 9049936 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-31 15:00 . 2011-09-09 19:14 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-12 04:10 . 2011-08-22 23:14 8862544 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-08-08 10:41 . 2011-06-20 13:53 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-08 08:00 . 2010-02-14 13:47 74752 ----a-w- c:\windows\SysWow64\ff_vfw.dll
2011-07-29 11:39 . 2011-07-29 11:39 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll
2011-07-29 11:35 . 2011-03-16 21:26 107832 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-29 11:35 . 2011-07-29 11:35 2250024 ----a-w- c:\windows\SysWow64\pbsvc.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-26_17.24.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2011-10-26 19:29 41202 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-02-19 14:54 . 2011-10-26 19:29 13128 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1802900682-2671537665-57566100-1000_UserData.bin
- 2011-02-19 18:04 . 2011-10-26 17:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-02-19 18:04 . 2011-10-26 19:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-02-19 18:04 . 2011-10-26 17:03 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-19 18:04 . 2011-10-26 19:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-26 19:27 . 2011-10-26 19:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-26 16:48 . 2011-10-26 16:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-10-26 16:48 . 2011-10-26 16:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-10-26 19:27 . 2011-10-26 19:27 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 05:01 . 2011-10-26 16:47 456304 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-10-26 19:26 456304 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:34 . 2011-09-09 18:57 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-10-26 18:11 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMBooster"="c:\program files (x86)\Iminent\IMBooster\imbooster.exe" [2011-03-30 1324008]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableThumbnails"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [x]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-09-27 2027840]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys [x]
S3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys [x]
S3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-07-07 11856]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-09-01 07:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [BU]
"combofix"="c:\combofix\CF24606.3XE" [2009-07-14 344576]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 173.193.227.124 173.192.105.217
FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\750yqnxa.default\
FF - Ext: Iminent WebBooster: webbooster@iminent.com - c:\program files (x86)\Mozilla Firefox\extensions\webbooster@iminent.com
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
BHO-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
BHO-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-BabylonToolbar - c:\program files (x86)\BabylonToolbar\BabylonToolbar\1.4.31.2\uninstall.exe
AddRemove-BitTorrentBar Toolbar - c:\progra~2\BITTOR~2\UNWISE.EXE
.
.
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Google\Update\GoogleUpdate.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\PnkBstrB.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files (x86)\VideoLAN\VLC\vlc.exe
c:\program files (x86)\TuneUp Utilities 2011\OneClick.exe
.
**************************************************************************
.
Completion time: 2011-10-26 21:34:11 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-26 19:34
ComboFix2.txt 2011-10-26 17:40
.
Pre-Run: 9 086 910 464 bytes free
Post-Run: 8 809 623 552 bytes free
.
- - End Of File - - DA7DA866D4FD7FF4090E1E8B1C6EDCC4

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#12 Příspěvek od vyosek »

Jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

*AdR!cK*
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 26 říj 2011 16:56

Re: Pls Kontrola logu

#13 Příspěvek od *AdR!cK* »

vyosek píše:Jak se chova PC :???:
Uz tak nemrzne ... a log je uz cisty?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Pls Kontrola logu

#14 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Nainstalujte Service Pack 1 pro W7 - resi mnoho chyb a problemu

:arrow: Poprosim o novy log z RSIT a napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět