
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosim o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosim o kontrolu
Zdravim po dlhsom case som spustil kontrolu a naslo mi toto...SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/25/2012 at 12:00 PM
Application Version : 5.0.1142
Core Rules Database Version : 8164
Trace Rules Database Version: 5976
Scan type : Quick Scan
Total Scan Time : 00:04:49
Operating System Information
Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User
Memory items scanned : 503
Memory threats detected : 0
Registry items scanned : 30921
Registry threats detected : 0
File items scanned : 10366
File threats detected : 217
Adware.Tracking Cookie
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\7MZR1N1O.txt [ /atdmt.com ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\ZZOGZOAP.txt [ /doubleclick.net ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\UK7ZU7TM.txt [ /c.atdmt.com ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\8MXJQ613.txt [ /advertising.com ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\ZZOGZOAP.txt [ Cookie:universal@doubleclick.net/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\UK7ZU7TM.txt [ Cookie:universal@c.atdmt.com/ ]
C:\USERS\UNIVERSAL\Cookies\8MXJQ613.txt [ Cookie:universal@advertising.com/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.pro-market.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
server.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.r1-ads.ace.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
advert.uloz.to [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ads.ventivmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ww25.embed.livesexdownload.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.userporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.192com.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.googleads.g.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.afe2.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.www.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.pornrabbit.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.stats.ebay.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.view.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.aimfar.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www4.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
oasn-en1.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
sk.static.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.toplist.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
http://www.superantispyware.com
Generated 01/25/2012 at 12:00 PM
Application Version : 5.0.1142
Core Rules Database Version : 8164
Trace Rules Database Version: 5976
Scan type : Quick Scan
Total Scan Time : 00:04:49
Operating System Information
Windows 7 Professional 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User
Memory items scanned : 503
Memory threats detected : 0
Registry items scanned : 30921
Registry threats detected : 0
File items scanned : 10366
File threats detected : 217
Adware.Tracking Cookie
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\7MZR1N1O.txt [ /atdmt.com ]
.overture.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\ZZOGZOAP.txt [ /doubleclick.net ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\UK7ZU7TM.txt [ /c.atdmt.com ]
C:\Users\universal\AppData\Roaming\Microsoft\Windows\Cookies\8MXJQ613.txt [ /advertising.com ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.at.atwola.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\ZZOGZOAP.txt [ Cookie:universal@doubleclick.net/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
C:\USERS\UNIVERSAL\Cookies\UK7ZU7TM.txt [ Cookie:universal@c.atdmt.com/ ]
C:\USERS\UNIVERSAL\Cookies\8MXJQ613.txt [ Cookie:universal@advertising.com/ ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.yieldmanager.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.pro-market.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
bmuk.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstbeacon.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.lucidmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adviva.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
server.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adformdsp.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.apmebf.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.r1-ads.ace.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tradedoubler.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
advert.uloz.to [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ads.ventivmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ww25.embed.livesexdownload.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.userporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.192com.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.googleads.g.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.statcounter.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpose.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.afe2.specificclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.ru4.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.baa.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.casalemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.questionmarket.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.collective-media.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
track.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adform.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.exodustravel.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.www.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.mediaplex.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.pornrabbit.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.hardsextube.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adxpansion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.stats.ebay.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.paypal.112.2o7.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.traveladvertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adbrite.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.googleadservices.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.burstnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.view.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.bs.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.tribalfusion.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.serving-sys.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
statse.webtrendslive.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.media6degrees.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.revsci.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.fastclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.zedo.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.aimfar.solution.weborama.fr [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.adtech.de [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.clickfuse.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www4.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.atdmt.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.advertising.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
www.smartadserver.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
oasn-en1.247realmedia.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.youporn.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.porno.kinotip.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
ad.yieldmanager.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
sk.static.etargetnet.com [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
.toplist.cz [ C:\USERS\UNIVERSAL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\80CCG3JP.DEFAULT\COOKIES.SQLITE ]
Re: prosim o kontrolu
ahoj,
mozes dat vsetko zmazat ,,, cookies vsak nepredstavuju vyznamnejsiu hrozbu, takze nabuduce sa ozvi ak SaS najde aj cosi ine ako cookies
mozes dat vsetko zmazat ,,, cookies vsak nepredstavuju vyznamnejsiu hrozbu, takze nabuduce sa ozvi ak SaS najde aj cosi ine ako cookies

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: prosim o kontrolu
OK DAKUJEM PRE ISTOTU POSIELAM LOG.Logfile of random's system information tool 1.09 (written by random/random)
Run by universal at 2012-01-25 12:22:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 22 GB (15%) free of 146 GB
Total RAM: 2814 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:22:13, on 25/01/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\program files (x86)\real\realplayer\update\realsched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\trend micro\universal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cas.sk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1320680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... nkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
R3 - URLSearchHook: (no name) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8344 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a9e263c0-5289-4dd8-9267-58da62ea8e22 -SystemEventPortName:HostProcess-03daa10f-e42b-4b47-9e9e-ffdbb738dead -IoCancelEventPortName:HostProcess-5f09130f-1cc3-4979-afd4-8c9d480a9e8a -NonStateChangingEventPortName:HostProcess-7cc37bcc-3b17-4cc6-aaa1-b9cae737baad -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d4d3286e-da7b-4c02-a164-a4b380bd99b8
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
"C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3356.d2477b0.539878765 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 3356 "\\.\pipe\gecko-crash-server-pipe.3356" plugin
"c:\program files (x86)\real\realplayer\update\realsched.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\universal\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT13206 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "chrome://browser-region/locale/region.properties"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0]
"Description"=DivX® Content Upload Plugin
"Path"=C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666]
"Description"=12.0.1.666
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsjsrealplayerplugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npDivxPlayerPlugin.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
nsIDivxPlayerPlugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
babylon.xml
bing.xml
eBay.xml
google.xml
SearchResults.xml
twitter.xml
wikipedia.xml
yahoo.xml
C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\extensions\
{3189af69-c0a1-4318-b2b9-610e0ba6a775}
{872b5b88-9db5-4310-bdd0-ac189557e5f5}
{f92a9fe4-2850-4198-b9d5-279880e49b16}
C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\searchplugins\
conduit.xml
SearchResults.xml
uloto.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll [2008-07-29 378416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-09-10 414416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [2008-07-29 181296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-07-29 142896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-28 16334880]
"eDataSecurity Loader"=C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe [2008-07-29 561200]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"=C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-12-16 5486464]
"Google Update"=C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 136176]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2011-09-10 273528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-01-25 12:22:08 ----D---- C:\rsit
2012-01-16 20:50:35 ----D---- C:\Windows\Minidump
2012-01-11 18:18:56 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-11 18:18:54 ----A---- C:\Windows\system32\qdvd.dll
2012-01-11 18:18:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-11 18:18:53 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 18:18:52 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-11 18:18:52 ----A---- C:\Windows\system32\packager.dll
2012-01-01 19:28:59 ----D---- C:\Users\universal\AppData\Roaming\iWin
2012-01-01 19:24:00 ----A---- C:\Windows\SYSWOW64\Statistics.txt
2012-01-01 19:23:43 ----A---- C:\Windows\GPlrLanc.dat
======List of files/folders modified in the last 1 month======
2012-01-25 12:22:13 ----D---- C:\Windows\Prefetch
2012-01-25 12:22:12 ----D---- C:\Program Files\trend micro
2012-01-25 12:22:00 ----D---- C:\Windows\Temp
2012-01-25 07:23:26 ----D---- C:\Windows\system32\config
2012-01-24 13:27:46 ----D---- C:\Windows\system32\catroot2
2012-01-24 12:48:10 ----D---- C:\Windows\winsxs
2012-01-24 12:48:08 ----SHD---- C:\Windows\Installer
2012-01-24 12:47:52 ----SHD---- C:\System Volume Information
2012-01-23 15:56:50 ----D---- C:\Users\universal\AppData\Roaming\Skype
2012-01-22 10:47:07 ----D---- C:\Windows
2012-01-21 09:53:23 ----D---- C:\Windows\System32
2012-01-21 09:53:23 ----D---- C:\Windows\inf
2012-01-21 09:53:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-14 11:19:55 ----D---- C:\Windows\debug
2012-01-12 22:16:09 ----D---- C:\Windows\system32\wdi
2012-01-11 21:03:40 ----D---- C:\Windows\SysWOW64
2012-01-11 21:03:40 ----D---- C:\Windows\ehome
2012-01-11 20:15:48 ----A---- C:\Windows\system32\MRT.exe
2012-01-11 18:18:46 ----D---- C:\Windows\system32\catroot
2012-01-11 03:43:47 ----D---- C:\Windows\Microsoft.NET
2012-01-11 03:43:24 ----RSD---- C:\Windows\assembly
2012-01-10 23:18:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-09 20:52:05 ----A---- C:\Users\universal\AppData\Roaming\burnaware.ini
2012-01-08 11:00:33 ----D---- C:\Windows\system32\NDF
2012-01-05 12:03:10 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-05 12:03:02 ----D---- C:\Windows\system32\drivers
2012-01-02 12:28:23 ----RD---- C:\Program Files (x86)
2012-01-02 12:20:56 ----D---- C:\Windows\SYSWOW64\drivers
2012-01-01 20:44:43 ----D---- C:\Windows\system32\Tasks
2012-01-01 20:44:32 ----HD---- C:\ProgramData
2012-01-01 20:44:32 ----D---- C:\Windows\Downloaded Program Files
2011-12-26 20:54:06 ----D---- C:\Program Files (x86)\Google
2011-12-26 20:52:35 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-07-29 22064]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-10 503352]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 MpKslc42c43e2;MpKslc42c43e2; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFB5E570-20E8-43FD-B38F-4AA24CA62AFB}\MpKslc42c43e2.sys [2012-01-25 35664]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 21040]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60976]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 winbondcir;Winbond IR Transceiver; C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 46592]
S1 chxkdnhe;chxkdnhe; \??\C:\Windows\system32\drivers\chxkdnhe.sys []
S1 DritekPortIO;Dritek General Port I/O; \??\C:\Program Files (x86)\Launch Manager\DPortIO.sys []
S1 gccaphui;gccaphui; \??\C:\Windows\system32\drivers\gccaphui.sys []
S3 ajt7r0nc;ajt7r0nc; C:\Windows\system32\drivers\ajt7r0nc.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2010-04-14 54824]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-12-10 23152]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\Windows\system32\DRIVERS\s716bus.sys [2007-04-04 108296]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-28 382496]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-28 1255736]
S4 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
-----------------EOF-----------------
Run by universal at 2012-01-25 12:22:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 22 GB (15%) free of 146 GB
Total RAM: 2814 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:22:13, on 25/01/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
c:\program files (x86)\real\realplayer\update\realsched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\trend micro\universal.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cas.sk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1320680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId= ... nkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
R3 - URLSearchHook: (no name) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8344 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-a9e263c0-5289-4dd8-9267-58da62ea8e22 -SystemEventPortName:HostProcess-03daa10f-e42b-4b47-9e9e-ffdbb738dead -IoCancelEventPortName:HostProcess-5f09130f-1cc3-4979-afd4-8c9d480a9e8a -NonStateChangingEventPortName:HostProcess-7cc37bcc-3b17-4cc6-aaa1-b9cae737baad -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d4d3286e-da7b-4c02-a164-a4b380bd99b8
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
"C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE"
"C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3356.d2477b0.539878765 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 3356 "\\.\pipe\gecko-crash-server-pipe.3356" plugin
"c:\program files (x86)\real\realplayer\update\realsched.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe"
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\universal\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://search.conduit.com/?ctid=CT13206 ... hSource=13"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94, {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "chrome://browser-region/locale/region.properties"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0]
"Description"=DivX® Content Upload Plugin
"Path"=C:\Program Files (x86)\DivX\DivX Content Uploader\npUpload.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666]
"Description"=RealJukebox Netscape Plugin
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666]
"Description"=RealNetworks(tm) RealPlayer Chrome Background Extension Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666]
"Description"=12.0.1.666
"Path"=c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsjsrealplayerplugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npDivxPlayerPlugin.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
nsIDivxPlayerPlugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
babylon.xml
bing.xml
eBay.xml
google.xml
SearchResults.xml
twitter.xml
wikipedia.xml
yahoo.xml
C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\extensions\
{3189af69-c0a1-4318-b2b9-610e0ba6a775}
{872b5b88-9db5-4310-bdd0-ac189557e5f5}
{f92a9fe4-2850-4198-b9d5-279880e49b16}
C:\Users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\searchplugins\
conduit.xml
SearchResults.xml
uloto.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll [2008-07-29 378416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2011-09-10 414416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9}]
DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-02-08 3118976]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll [2008-07-29 181296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-07-29 142896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-28 16334880]
"eDataSecurity Loader"=C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe [2008-07-29 561200]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"=C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [2010-08-09 248832]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2011-12-16 5486464]
"Google Update"=C:\Users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 136176]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"TkBellExe"=c:\program files (x86)\real\realplayer\Update\realsched.exe [2011-09-10 273528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-01-25 12:22:08 ----D---- C:\rsit
2012-01-16 20:50:35 ----D---- C:\Windows\Minidump
2012-01-11 18:18:56 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-11 18:18:55 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-11 18:18:54 ----A---- C:\Windows\system32\qdvd.dll
2012-01-11 18:18:53 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-11 18:18:53 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 18:18:52 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-11 18:18:52 ----A---- C:\Windows\system32\packager.dll
2012-01-01 19:28:59 ----D---- C:\Users\universal\AppData\Roaming\iWin
2012-01-01 19:24:00 ----A---- C:\Windows\SYSWOW64\Statistics.txt
2012-01-01 19:23:43 ----A---- C:\Windows\GPlrLanc.dat
======List of files/folders modified in the last 1 month======
2012-01-25 12:22:13 ----D---- C:\Windows\Prefetch
2012-01-25 12:22:12 ----D---- C:\Program Files\trend micro
2012-01-25 12:22:00 ----D---- C:\Windows\Temp
2012-01-25 07:23:26 ----D---- C:\Windows\system32\config
2012-01-24 13:27:46 ----D---- C:\Windows\system32\catroot2
2012-01-24 12:48:10 ----D---- C:\Windows\winsxs
2012-01-24 12:48:08 ----SHD---- C:\Windows\Installer
2012-01-24 12:47:52 ----SHD---- C:\System Volume Information
2012-01-23 15:56:50 ----D---- C:\Users\universal\AppData\Roaming\Skype
2012-01-22 10:47:07 ----D---- C:\Windows
2012-01-21 09:53:23 ----D---- C:\Windows\System32
2012-01-21 09:53:23 ----D---- C:\Windows\inf
2012-01-21 09:53:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-14 11:19:55 ----D---- C:\Windows\debug
2012-01-12 22:16:09 ----D---- C:\Windows\system32\wdi
2012-01-11 21:03:40 ----D---- C:\Windows\SysWOW64
2012-01-11 21:03:40 ----D---- C:\Windows\ehome
2012-01-11 20:15:48 ----A---- C:\Windows\system32\MRT.exe
2012-01-11 18:18:46 ----D---- C:\Windows\system32\catroot
2012-01-11 03:43:47 ----D---- C:\Windows\Microsoft.NET
2012-01-11 03:43:24 ----RSD---- C:\Windows\assembly
2012-01-10 23:18:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-09 20:52:05 ----A---- C:\Users\universal\AppData\Roaming\burnaware.ini
2012-01-08 11:00:33 ----D---- C:\Windows\system32\NDF
2012-01-05 12:03:10 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-05 12:03:02 ----D---- C:\Windows\system32\drivers
2012-01-02 12:28:23 ----RD---- C:\Program Files (x86)
2012-01-02 12:20:56 ----D---- C:\Windows\SYSWOW64\drivers
2012-01-01 20:44:43 ----D---- C:\Windows\system32\Tasks
2012-01-01 20:44:32 ----HD---- C:\ProgramData
2012-01-01 20:44:32 ----D---- C:\Windows\Downloaded Program Files
2011-12-26 20:54:06 ----D---- C:\Program Files (x86)\Google
2011-12-26 20:52:35 ----D---- C:\Windows\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-07-29 22064]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-10 503352]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 MpKslc42c43e2;MpKslc42c43e2; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CFB5E570-20E8-43FD-B38F-4AA24CA62AFB}\MpKslc42c43e2.sys [2012-01-25 35664]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-07-29 21040]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-07-29 60976]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
R3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
R3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
R3 winbondcir;Winbond IR Transceiver; C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 46592]
S1 chxkdnhe;chxkdnhe; \??\C:\Windows\system32\drivers\chxkdnhe.sys []
S1 DritekPortIO;Dritek General Port I/O; \??\C:\Program Files (x86)\Launch Manager\DPortIO.sys []
S1 gccaphui;gccaphui; \??\C:\Windows\system32\drivers\gccaphui.sys []
S3 ajt7r0nc;ajt7r0nc; C:\Windows\system32\drivers\ajt7r0nc.sys []
S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2010-04-14 54824]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-12-10 23152]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 s716bus;Sony Ericsson Device 716 driver (WDM); C:\Windows\system32\DRIVERS\s716bus.sys [2007-04-04 108296]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-07-29 500784]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-28 382496]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-28 1255736]
S4 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
-----------------EOF-----------------
Re: prosim o kontrolu
cosi drobne sa tam nachadza
Presun ComboFix
na plochu (ak tam este nie je)
otvor si Poznamkovy blok - notepad
do neho zkopiruj skript z nasledujiceho okna:
uloz vytvoreny textovy soubor ako CFScript.txt na plochu
po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

po aplikacii by mal vzniknut dalsi log, ten vloz sem

Presun ComboFix
na plochu (ak tam este nie je)
otvor si Poznamkovy blok - notepad
do neho zkopiruj skript z nasledujiceho okna:
Kód: Vybrat vše
Driver::
chxkdnhe
gccaphui
po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

po aplikacii by mal vzniknut dalsi log, ten vloz sem

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: prosim o kontrolu
ComboFix 12-02-21.02 - universal 21/02/2012 19:34:07.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.2814.1632 [GMT 0:00]
Running from: c:\users\universal\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2012-01-21 to 2012-02-21 )))))))))))))))))))))))))))))))
.
.
2012-02-21 19:42 . 2012-02-21 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\users\universal\AppData\Roaming\Ashampoo
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\ConduitEngine
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\MyAshampoo
2012-02-21 19:03 . 2012-02-21 19:03 -------- d-----w- c:\program files (x86)\Ashampoo
2012-02-21 16:22 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5C977D5E-B18E-46F6-9E36-A08AB339B103}\mpengine.dll
2012-02-21 11:44 . 2012-02-21 11:44 -------- d-----w- c:\program files (x86)\True Burner
2012-02-20 13:01 . 2012-02-20 13:02 -------- d-----w- c:\program files (x86)\PC Speed Up
2012-02-20 12:58 . 2012-02-20 12:58 -------- d-----w- c:\program files (x86)\DealPly
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\programdata\NCH Software
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\program files (x86)\NCH Software
2012-02-20 12:44 . 2012-02-20 12:50 -------- d-----w- c:\users\universal\AppData\Roaming\NCH Software
2012-02-15 23:32 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-15 23:32 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 23:32 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-15 23:32 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 23:32 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 23:32 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 23:32 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 23:32 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-10 18:04 . 2012-02-10 18:03 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7F5FEF97-6E59-4196-8851-EBC56F583C18}\gapaengine.dll
2012-01-25 12:22 . 2012-01-25 12:22 -------- d-----w- C:\rsit
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 16:44 . 2011-05-18 22:56 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-08 07:13 . 2011-02-07 19:18 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-01-28 17:06 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-12-14 18:45 . 2011-03-04 11:29 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-12-10 15:24 . 2011-02-08 21:15 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-04 06:20 . 2011-02-15 15:16 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\MyAshampoo\tbMyAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:52 121392 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-02-05 5487488]
"PCSpeedUp"="c:\program files (x86)\PC Speed Up\PCSpeedUp.lnk" [2012-02-20 2125]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-09-10 273528]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 chxkdnhe;chxkdnhe;c:\windows\system32\drivers\chxkdnhe.sys [x]
R1 gccaphui;gccaphui;c:\windows\system32\drivers\gccaphui.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Speed Up\PCSUService.exe [2011-10-24 235232]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:53 50736 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-28 16334880]
"eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-29 561200]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1320680&SearchSource=13
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
URLSearchHooks-{f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
Toolbar-10 - (no file)
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-21 19:46:09
ComboFix-quarantined-files.txt 2012-02-21 19:46
ComboFix2.txt 2012-01-25 13:20
.
Pre-Run: 32,325,406,720 bytes free
Post-Run: 32,246,542,336 bytes free
.
- - End Of File - - 5BC128910E8F3A668CCD06DB48D9EC72
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1033.18.2814.1632 [GMT 0:00]
Running from: c:\users\universal\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2012-01-21 to 2012-02-21 )))))))))))))))))))))))))))))))
.
.
2012-02-21 19:42 . 2012-02-21 19:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\users\universal\AppData\Roaming\Ashampoo
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\ConduitEngine
2012-02-21 19:04 . 2012-02-21 19:04 -------- d-----w- c:\program files (x86)\MyAshampoo
2012-02-21 19:03 . 2012-02-21 19:03 -------- d-----w- c:\program files (x86)\Ashampoo
2012-02-21 16:22 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5C977D5E-B18E-46F6-9E36-A08AB339B103}\mpengine.dll
2012-02-21 11:44 . 2012-02-21 11:44 -------- d-----w- c:\program files (x86)\True Burner
2012-02-20 13:01 . 2012-02-20 13:02 -------- d-----w- c:\program files (x86)\PC Speed Up
2012-02-20 12:58 . 2012-02-20 12:58 -------- d-----w- c:\program files (x86)\DealPly
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\programdata\NCH Software
2012-02-20 12:44 . 2012-02-20 12:44 -------- d-----w- c:\program files (x86)\NCH Software
2012-02-20 12:44 . 2012-02-20 12:50 -------- d-----w- c:\users\universal\AppData\Roaming\NCH Software
2012-02-15 23:32 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-15 23:32 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 23:32 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-15 23:32 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 23:32 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 23:32 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 23:32 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 23:32 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-10 18:04 . 2012-02-10 18:03 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7F5FEF97-6E59-4196-8851-EBC56F583C18}\gapaengine.dll
2012-01-25 12:22 . 2012-01-25 12:22 -------- d-----w- C:\rsit
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 16:44 . 2011-05-18 22:56 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-08 07:13 . 2011-02-07 19:18 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-01-28 17:06 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-12-14 18:45 . 2011-03-04 11:29 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-12-10 15:24 . 2011-02-08 21:15 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-04 06:20 . 2011-02-15 15:16 710992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2010-11-29 15:26 3908192 ----a-w- c:\program files (x86)\MyAshampoo\tbMyAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files (x86)\MyAshampoo\tbMyAs.dll" [2010-11-29 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:52 121392 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-02-05 5487488]
"PCSpeedUp"="c:\program files (x86)\PC Speed Up\PCSpeedUp.lnk" [2012-02-20 2125]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2011-09-10 273528]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R1 chxkdnhe;chxkdnhe;c:\windows\system32\drivers\chxkdnhe.sys [x]
R1 gccaphui;gccaphui;c:\windows\system32\drivers\gccaphui.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 136176]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-18 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 PCSUService;PC Speed Up Service;c:\program files (x86)\PC Speed Up\PCSUService.exe [2011-10-24 235232]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-26 20:52]
.
2012-02-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000Core.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1534005465-471312124-3077132656-1000UA.job
- c:\users\universal\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-28 17:07]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 17:53 50736 ----a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-28 16334880]
"eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-29 561200]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2475029
uDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\users\universal\AppData\Roaming\Mozilla\Firefox\Profiles\80ccg3jp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1320680&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1320680&SearchSource=13
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
URLSearchHooks-{f92a9fe4-2850-4198-b9d5-279880e49b16} - (no file)
Toolbar-10 - (no file)
Toolbar-10 - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-21 19:46:09
ComboFix-quarantined-files.txt 2012-02-21 19:46
ComboFix2.txt 2012-01-25 13:20
.
Pre-Run: 32,325,406,720 bytes free
Post-Run: 32,246,542,336 bytes free
.
- - End Of File - - 5BC128910E8F3A668CCD06DB48D9EC72
Re: prosim o kontrolu
Jak je na tom počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosim o kontrolu
zdravim...notebuk ide vsetko aj sa zrychlil ..no nechce sa restartovat len sa vypne...ani cez F8 sa nedostanem do nuzoveho rezimu..trva to asi 15 /20 minut kym sa mi ho podari zapnut
Re: prosim o kontrolu

http://www.slunecnice.cz/sw/crystaldiskinfo/
- spusťte ho a v nabídce zvolte Kopírovat.
-Data ze schránky sem pak vložte pomocí Ctrl+V
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosim o kontrolu
----------------------------------------------------------------------------
CrystalDiskInfo 4.1.3 (C) 2008-2011 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 SP1 [6.1 Build 7601] (x64)
Date : 2012/02/25 22:30:56
-- Controller Map ----------------------------------------------------------
+ Standard AHCI 1.0 Serial ATA Controller [ATA]
+ ATA Channel 0 (0)
- Hitachi HTS543232L9A300 ATA Device
- ATA Channel 1 (1)
+ ATA Channel 2 (2)
- HL-DT-ST DVDRAM GSA-T50N ATA Device
- ATA Channel 3 (3)
- ATA Channel 4 (4)
- ATA Channel 5 (5)
-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS543232L9A300 : 320.0 GB [0-0-0, pd1]
----------------------------------------------------------------------------
(1) Hitachi HTS543232L9A300
----------------------------------------------------------------------------
Model : Hitachi HTS543232L9A300
Firmware : FB4OC40C
Serial Number : 080918FB2400LEC5WPDA
Disk Size : 320.0 GB (8.4/137.4/320.0)
Buffer Size : 7114 KB
Queue Depth : 32
# of Sectors : 625142448
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 3f
Transfer Mode : SATA/300
Power On Hours : 7940 hod.
Power On Count : 4405 krát
Temparature : 32 C (89 F)
Health Status : Pozor
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 253 253 _33 000400000000 Čas na roztočení ploten
04 _98 _98 __0 000000001163 Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _82 _82 __0 000000001F04 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _98 _98 __0 000000001135 Počet cyklů zapnutí zařízení
BF 100 100 __0 000000000000 Počet udalostí zaznamenaných otřesovým senzorem
C0 _96 _96 __0 0000000003C8 Počet vypnutí disku
C1 _91 _91 __0 000000016C93 Počet cyklů načítání/vymazání
C2 171 171 __0 003300070020 Teplota
C4 100 100 __0 000000000002 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000001 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000003 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony
-- IDENTIFY_DEVICE ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 04 5A 3F FF C8 37 00 10 00 00 00 00 00 3F 00 00
010: 00 00 00 00 30 38 30 39 31 38 46 42 32 34 30 30
020: 4C 45 43 35 57 50 44 41 00 03 37 95 00 04 46 42
030: 34 4F 43 34 30 43 48 69 74 61 63 68 69 20 48 54
040: 53 35 34 33 32 33 32 4C 39 41 33 30 30 20 20 20
050: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 80 10
060: 40 00 0F 00 40 00 02 00 02 00 00 07 3F FF 00 10
070: 00 3F FC 10 00 FB 01 10 FF FF 0F FF 00 00 00 07
080: 00 03 00 78 00 78 00 78 00 78 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 1F 17 06 00 00 00 5E 00 40
0A0: 01 FC 00 42 74 6B 7F 69 61 63 74 69 BC 49 61 63
0B0: 40 7F 00 3F 00 40 40 80 00 01 00 00 80 FE 00 00
0C0: 00 00 00 00 00 00 00 00 EA B0 25 42 00 00 00 00
0D0: 00 00 00 00 00 00 88 48 50 00 CC A5 64 C2 AD CD
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 14
0F0: 40 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 29 00 0B 00 09 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 40 01 00 00 80 00 00 00
130: 34 4F 00 00 00 00 74 74 63 63 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 3D 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 15 18 00 00 00 00 00 00 00 00 10 1F 00 21
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 01 00 80 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A7 A5
CrystalDiskInfo 4.1.3 (C) 2008-2011 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------
OS : Windows 7 SP1 [6.1 Build 7601] (x64)
Date : 2012/02/25 22:30:56
-- Controller Map ----------------------------------------------------------
+ Standard AHCI 1.0 Serial ATA Controller [ATA]
+ ATA Channel 0 (0)
- Hitachi HTS543232L9A300 ATA Device
- ATA Channel 1 (1)
+ ATA Channel 2 (2)
- HL-DT-ST DVDRAM GSA-T50N ATA Device
- ATA Channel 3 (3)
- ATA Channel 4 (4)
- ATA Channel 5 (5)
-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS543232L9A300 : 320.0 GB [0-0-0, pd1]
----------------------------------------------------------------------------
(1) Hitachi HTS543232L9A300
----------------------------------------------------------------------------
Model : Hitachi HTS543232L9A300
Firmware : FB4OC40C
Serial Number : 080918FB2400LEC5WPDA
Disk Size : 320.0 GB (8.4/137.4/320.0)
Buffer Size : 7114 KB
Queue Depth : 32
# of Sectors : 625142448
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 3f
Transfer Mode : SATA/300
Power On Hours : 7940 hod.
Power On Count : 4405 krát
Temparature : 32 C (89 F)
Health Status : Pozor
Features : S.M.A.R.T., APM, AAM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : 80FEh [OFF]
-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 253 253 _33 000400000000 Čas na roztočení ploten
04 _98 _98 __0 000000001163 Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _82 _82 __0 000000001F04 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C _98 _98 __0 000000001135 Počet cyklů zapnutí zařízení
BF 100 100 __0 000000000000 Počet udalostí zaznamenaných otřesovým senzorem
C0 _96 _96 __0 0000000003C8 Počet vypnutí disku
C1 _91 _91 __0 000000016C93 Počet cyklů načítání/vymazání
C2 171 171 __0 003300070020 Teplota
C4 100 100 __0 000000000002 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000001 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000003 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony
-- IDENTIFY_DEVICE ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 04 5A 3F FF C8 37 00 10 00 00 00 00 00 3F 00 00
010: 00 00 00 00 30 38 30 39 31 38 46 42 32 34 30 30
020: 4C 45 43 35 57 50 44 41 00 03 37 95 00 04 46 42
030: 34 4F 43 34 30 43 48 69 74 61 63 68 69 20 48 54
040: 53 35 34 33 32 33 32 4C 39 41 33 30 30 20 20 20
050: 20 20 20 20 20 20 20 20 20 20 20 20 20 20 80 10
060: 40 00 0F 00 40 00 02 00 02 00 00 07 3F FF 00 10
070: 00 3F FC 10 00 FB 01 10 FF FF 0F FF 00 00 00 07
080: 00 03 00 78 00 78 00 78 00 78 00 00 00 00 00 00
090: 00 00 00 00 00 00 00 1F 17 06 00 00 00 5E 00 40
0A0: 01 FC 00 42 74 6B 7F 69 61 63 74 69 BC 49 61 63
0B0: 40 7F 00 3F 00 40 40 80 00 01 00 00 80 FE 00 00
0C0: 00 00 00 00 00 00 00 00 EA B0 25 42 00 00 00 00
0D0: 00 00 00 00 00 00 88 48 50 00 CC A5 64 C2 AD CD
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 14
0F0: 40 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 29 00 0B 00 09 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 40 01 00 00 80 00 00 00
130: 34 4F 00 00 00 00 74 74 63 63 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 3D 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 15 18 00 00 00 00 00 00 00 00 10 1F 00 21
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 01 00 80 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A7 A5
Re: prosim o kontrolu
Ten disk pořádně prověříme
Stahněte HD tune http://www.slunecnice.cz/sw/hd-tune/
-zvolete poslední záložku Error scan
-dejte skenovat, trvá to kolem hodiny.
-pak napište jestli jste měl nějaká políčka červená

-zvolete poslední záložku Error scan
-dejte skenovat, trvá to kolem hodiny.
-pak napište jestli jste měl nějaká políčka červená
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosim o kontrolu
zdravim..spustil som ten sken ...cervene policko ziadne...damaged blocks 0.0 percent
Re: prosim o kontrolu
Ten disk podle mě není uplně v pořádku, může být poškozený nějaký systémový soubor....zazálohujte si svoje data a udělejte kontrolu disku.
start-spustit - napište chkdsk /f/r
-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat

-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosim o kontrolu
nepusti mne to tam....napisu dam entr jen problikne a nic se nedeje...ani jako admin mne tam nechce pustit....
Re: prosim o kontrolu
este dalsia zavada z nicoho nic mi prestal fungovat burner ,neda sa napalit dvd,skusil som stiahnut i ine programy na vypalovanie no bez vysledku stale mi to hlasi nezdarilo sa vypalovanie...
Re: prosim o kontrolu
Tento počítač - disk C - klik pravým tlačítkem - vlastnosti - nástroje - kontrola chyb svazku.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.