
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Pravdepodobne infikovaný notebook. (RSIT log)
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pravdepodobne infikovaný notebook. (RSIT log)
Zdravím, problém mám už nejaké týždne ale samému sa mi to nedarí spraviť, mazal som pomocou CCleaner-a aj antivirákom (Avast) kontroloval ale žiadnu infikáciu nenašlo, a musí niečo byť, notebook je strašne pomalý, a aj zamrzáva. Log z RSIT a robil som aj COMBOFIX.
Logfile of random's system information tool 1.09 (written by random/random)
Run by johny at 2012-10-31 09:07:39
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 72 GB (49%) free of 148 GB
Total RAM: 3066 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:49, on 31. 10. 2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Users\johny\Downloads\RSIT.exe
C:\Program Files\trend micro\johny.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE
O4 - HKLM\..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\RunOnce: [AcerScrSav] C:\Windows\Acer\run_NB.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Game Jackal Server (GJService) - Unknown owner - C:\ProgramData\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: KFJZNW - Unknown owner - C:\Users\johny\AppData\Local\Temp\KFJZNW.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: VECJ - Unknown owner - C:\Users\johny\AppData\Local\Temp\VECJ.exe (file missing)
--
End of file - 11349 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\ParetoLogic Registration3.job
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job
C:\Windows\tasks\ParetoLogic Update Version3.job
C:\Windows\tasks\RegCure Pro.job
=========Mozilla firefox=========
ProfilePath - C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://cs.start3.mozilla.com/firefox?cl ... s:official"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145, wrc@avast.com:7.0.1426"
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIBitCometAgent.xpt
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npBitCometAgent.dll
npdeploytk.dll
npDivxPlayerPlugin.dll
NPOFFICE.DLL
nsIDivxPlayerPlugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
Cetrumcz_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml
C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\
askcom.xml
conduit.xml
crawlersrch.xml
daemon-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-03-17 2355224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-23 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-08 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-03-17 2355224]
{D5D47440-0750-463D-BAEF-A47D02414806}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-23 1227224]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-28 6111232]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-04-23 397312]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-07-20 182808]
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-07-02 821768]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"=C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [2009-01-09 3607040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-05-12 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-05-12 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-05-12 167936]
"mouseElf"=C:\PROGRA~1\TWINTO~1\MouseElf.EXE [2004-08-26 192512]
"Startup Cleaner"=C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe [2006-07-14 118784]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-23 4297136]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-08-29 1996200]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-07-29 1259376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [2008-03-07 544768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-08-29 1996200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-02-12 723496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AWinNotifyVitaKey MC3000]
C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll [2009-01-09 2972160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Users\johny\AppData\Local\Temp\0.47319059924956774.exe"="C:\Users\johny\AppData\Local\Temp\0.47319059924956774.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\qanmbmim1eo2amtczyljflif2v2tyvu2\csrss.exe"="C:\Users\johny\AppData\Roaming\qanmbmim1eo2amtczyljflif2v2tyvu2\csrss.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\xrgu222ajguulzlmomftkdihr13hunhx2\svcnost.exe"="C:\Users\johny\AppData\Roaming\xrgu222ajguulzlmomftkdihr13hunhx2\svcnost.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\xkcganz3eng3w1xvcmdbhzrjfgvplpfq2\svcnost.exe"="C:\Users\johny\AppData\Roaming\xkcganz3eng3w1xvcmdbhzrjfgvplpfq2\svcnost.exe:*:Enabled:ldrsoft"
"D:\Hry\Combat Arms EU\CombatArms.exe"="D:\Hry\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\Hry\Combat Arms EU\Engine.exe"="D:\Hry\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"D:\Hry\Combat Arms EU\CombatArms.exe"="D:\Hry\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\Hry\Combat Arms EU\Engine.exe"="D:\Hry\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"VIDC.MKVC"=KMVIDC32.DLL
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.iv32"=C:\Windows\system32\ir32_32.dll
"vidc.iv31"=C:\Windows\system32\ir32_32.dll
"msacm.siren"=sirenacm.dll
"VIDC.CFHD"=cfhd.dll
"msacm.vorbis"=vorbis.acm
"VIDC.LAGS"=lagarith.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-10-31 08:39:55 ----D---- C:\Windows\temp
2012-10-31 08:39:54 ----A---- C:\ComboFix.txt
2012-10-31 08:38:40 ----SHD---- C:\$RECYCLE.BIN
2012-10-31 08:26:01 ----D---- C:\ComboFix
2012-10-30 18:37:31 ----A---- C:\Windows\system32\mshtmled.dll
2012-10-30 18:37:30 ----A---- C:\Windows\system32\vbscript.dll
2012-10-30 18:37:30 ----A---- C:\Windows\system32\ieui.dll
2012-10-30 18:37:29 ----A---- C:\Windows\system32\jsproxy.dll
2012-10-30 18:37:29 ----A---- C:\Windows\system32\ieUnatt.exe
2012-10-30 18:37:28 ----A---- C:\Windows\system32\msfeeds.dll
2012-10-30 18:37:27 ----A---- C:\Windows\system32\wininet.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\url.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\jscript9.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\jscript.dll
2012-10-30 18:37:24 ----A---- C:\Windows\system32\iertutil.dll
2012-10-30 18:37:23 ----A---- C:\Windows\system32\urlmon.dll
2012-10-30 18:37:21 ----A---- C:\Windows\system32\ieframe.dll
2012-10-30 18:37:20 ----A---- C:\Windows\system32\mshtml.dll
2012-10-30 18:20:50 ----A---- C:\Windows\system32\crypt32.dll
2012-10-30 18:20:49 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-30 18:20:49 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-30 18:20:40 ----A---- C:\Windows\system32\localspl.dll
2012-10-30 18:20:36 ----A---- C:\Windows\system32\wintrust.dll
2012-10-30 18:20:33 ----A---- C:\Windows\system32\netapi32.dll
2012-10-30 18:20:32 ----A---- C:\Windows\system32\win32k.sys
2012-10-30 18:19:20 ----A---- C:\Windows\system32\tzres.dll
2012-10-30 18:18:41 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-30 18:18:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-29 09:03:58 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2012-10-31 09:07:42 ----D---- C:\Program Files\Trend Micro
2012-10-31 08:54:43 ----D---- C:\Windows\system32\drivers
2012-10-31 08:39:56 ----D---- C:\Qoobox
2012-10-31 08:39:55 ----D---- C:\Windows
2012-10-31 08:37:35 ----A---- C:\Windows\system.ini
2012-10-31 08:36:41 ----D---- C:\ProgramData
2012-10-31 08:33:01 ----D---- C:\Windows\System32
2012-10-31 08:33:01 ----D---- C:\Windows\AppPatch
2012-10-31 08:32:58 ----D---- C:\Program Files\Common Files
2012-10-31 08:19:05 ----D---- C:\Windows\Prefetch
2012-10-31 07:45:27 ----SHD---- C:\Windows\Installer
2012-10-31 07:42:03 ----D---- C:\Users\johny\AppData\Roaming\Skype
2012-10-31 07:41:55 ----D---- C:\ProgramData\Skype
2012-10-31 07:41:29 ----RD---- C:\Program Files\Skype
2012-10-31 07:40:56 ----D---- C:\Windows\inf
2012-10-31 07:40:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-10-31 07:39:12 ----SHD---- C:\System Volume Information
2012-10-31 07:34:20 ----D---- C:\Logs
2012-10-30 19:37:46 ----D---- C:\Windows\rescache
2012-10-30 19:31:12 ----D---- C:\Users\johny\AppData\Roaming\Winamp
2012-10-30 19:31:12 ----D---- C:\Users\johny\AppData\Roaming\DAEMON Tools Lite
2012-10-30 19:31:11 ----D---- C:\Windows\Debug
2012-10-30 19:12:34 ----D---- C:\Windows\system32\sk-SK
2012-10-30 19:12:34 ----D---- C:\Windows\system32\migration
2012-10-30 19:12:34 ----D---- C:\Program Files\Internet Explorer
2012-10-30 18:37:55 ----D---- C:\Windows\winsxs
2012-10-30 18:37:52 ----D---- C:\Windows\system32\catroot
2012-10-30 18:37:51 ----D---- C:\Windows\system32\catroot2
2012-10-30 11:15:42 ----D---- C:\ProgramData\PMB Files
2012-10-30 10:01:58 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-29 12:16:26 ----RD---- C:\Program Files
2012-10-28 17:00:28 ----D---- C:\Windows\system32\Tasks
2012-10-23 12:17:38 ----A---- C:\Windows\system32\aswBoot.exe
2012-10-20 11:19:29 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-19 19:22:24 ----RSD---- C:\Windows\Fonts
2012-10-11 11:51:30 ----D---- C:\Windows\Minidump
2012-10-09 18:43:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AlfaFF;AlfaFF File System mini-filter; C:\Windows\system32\Drivers\AlfaFF.sys [2009-01-09 43184]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-07-20 324120]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-03-04 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-04 691696]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-30 13824]
R1 AswRdr;aswRdr; C:\Windows\system32\drivers\AswRdr.sys [2012-10-23 35928]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-23 738504]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-23 360392]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-23 54232]
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [2007-01-24 67584]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-05-09 61424]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-23 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-23 58680]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-02-01 279712]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2007-01-26 69632]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-02-01 25888]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2008-04-25 146688]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
R3 catchme;catchme; \??\C:\Users\johny\AppData\Local\Temp\catchme.sys []
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2008-07-02 21264]
R3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
R3 genmcmnUSB;USB Scroll Mouse Driver; C:\Windows\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-28 2127512]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-04-21 81296]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-11-12 122984]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-05-15 11354944]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winbondcir;Winbond IR Transceiver; C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 prodrv03;Star Force copy protection driver v3; C:\Windows\System32\drivers\prodrv03.sys [2009-01-13 115968]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys []
S3 aipad11g;aipad11g; C:\Windows\system32\drivers\aipad11g.sys []
S3 aura6dd0;aura6dd0; C:\Windows\system32\drivers\aura6dd0.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 CFcatchme;CFcatchme; \??\C:\Users\johny\AppData\Local\Temp\CFcatchme.sys []
S3 cimo;cimo; \??\C:\Windows\system32\cimo.sys [2009-08-05 51200]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\johny\AppData\Local\Temp\DRYD6E2.tmp []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-12-30 15600]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 Maplom;Maplom; C:\Windows\system32\drivers\Maplom.sys []
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster\Driver\WinRing0.sys [2010-11-01 14416]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\Windows\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-23 44808]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-10-16 860160]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-07-20 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-10-16 466944]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\Cyberlink\Shared files\RichVideo.exe [2007-01-09 272024]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 GJService;Game Jackal Server; C:\ProgramData\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe [2010-04-16 2031040]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2012-08-29 1385896]
S2 IGBASVC;iGroupTec Service; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [2009-01-09 3471360]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 KFJZNW;KFJZNW; C:\Users\johny\AppData\Local\Temp\KFJZNW.exe []
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-29 115168]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 VECJ;VECJ; C:\Users\johny\AppData\Local\Temp\VECJ.exe []
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by johny at 2012-10-31 09:07:39
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 72 GB (49%) free of 148 GB
Total RAM: 3066 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:49, on 31. 10. 2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Users\johny\Downloads\RSIT.exe
C:\Program Files\trend micro\johny.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Softonic-Eng7 Toolbar - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Softonic-Eng7 Toolbar - {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - C:\Program Files\Softonic-Eng7\tbSoft.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE
O4 - HKLM\..\Run: [Startup Cleaner] C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3966806968-2824471673-2848729136-1002\..\RunOnce: [AcerScrSav] C:\Windows\Acer\run_NB.exe (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Game Jackal Server (GJService) - Unknown owner - C:\ProgramData\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: KFJZNW - Unknown owner - C:\Users\johny\AppData\Local\Temp\KFJZNW.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: VECJ - Unknown owner - C:\Users\johny\AppData\Local\Temp\VECJ.exe (file missing)
--
End of file - 11349 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\ParetoLogic Registration3.job
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job
C:\Windows\tasks\ParetoLogic Update Version3.job
C:\Windows\tasks\RegCure Pro.job
=========Mozilla firefox=========
ProfilePath - C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://cs.start3.mozilla.com/firefox?cl ... s:official"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145, wrc@avast.com:7.0.1426"
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"=C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.4.402.287 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Plus Web Player
"Path"=C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIBitCometAgent.xpt
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npBitCometAgent.dll
npdeploytk.dll
npDivxPlayerPlugin.dll
NPOFFICE.DLL
nsIDivxPlayerPlugin.xpt
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
Cetrumcz_igeared.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
yahoo.xml
C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\
askcom.xml
conduit.xml
crawlersrch.xml
daemon-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-12-12 194432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-03-17 2355224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-03-04 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-23 1227224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-08 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-03-04 142896]
{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - Softonic-Eng7 Toolbar - C:\Program Files\Softonic-Eng7\tbSoft.dll [2010-03-17 2355224]
{D5D47440-0750-463D-BAEF-A47D02414806}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-23 1227224]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-28 6111232]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-01-18 1033512]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-03-04 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-04-23 397312]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-07-20 182808]
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-07-02 821768]
"PLFSetI"=C:\Windows\PLFSetI.exe [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"=C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [2009-01-09 3607040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-05-12 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-05-12 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-05-12 167936]
"mouseElf"=C:\PROGRA~1\TWINTO~1\MouseElf.EXE [2004-08-26 192512]
"Startup Cleaner"=C:\Program Files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe [2006-07-14 118784]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 153672]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-23 4297136]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-08-29 1996200]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2011-07-29 1259376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [2008-03-07 544768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2012-08-29 1996200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-02-12 723496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AWinNotifyVitaKey MC3000]
C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll [2009-01-09 2972160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Users\johny\AppData\Local\Temp\0.47319059924956774.exe"="C:\Users\johny\AppData\Local\Temp\0.47319059924956774.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\qanmbmim1eo2amtczyljflif2v2tyvu2\csrss.exe"="C:\Users\johny\AppData\Roaming\qanmbmim1eo2amtczyljflif2v2tyvu2\csrss.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\xrgu222ajguulzlmomftkdihr13hunhx2\svcnost.exe"="C:\Users\johny\AppData\Roaming\xrgu222ajguulzlmomftkdihr13hunhx2\svcnost.exe:*:Enabled:ldrsoft"
"C:\Users\johny\AppData\Roaming\xkcganz3eng3w1xvcmdbhzrjfgvplpfq2\svcnost.exe"="C:\Users\johny\AppData\Roaming\xkcganz3eng3w1xvcmdbhzrjfgvplpfq2\svcnost.exe:*:Enabled:ldrsoft"
"D:\Hry\Combat Arms EU\CombatArms.exe"="D:\Hry\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\Hry\Combat Arms EU\Engine.exe"="D:\Hry\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"D:\Hry\Combat Arms EU\CombatArms.exe"="D:\Hry\Combat Arms EU\CombatArms.exe:*Enabled:CombatArms.exe"
"D:\Hry\Combat Arms EU\Engine.exe"="D:\Hry\Combat Arms EU\Engine.exe:*Enabled:Engine.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"VIDC.MKVC"=KMVIDC32.DLL
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.iv32"=C:\Windows\system32\ir32_32.dll
"vidc.iv31"=C:\Windows\system32\ir32_32.dll
"msacm.siren"=sirenacm.dll
"VIDC.CFHD"=cfhd.dll
"msacm.vorbis"=vorbis.acm
"VIDC.LAGS"=lagarith.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-10-31 08:39:55 ----D---- C:\Windows\temp
2012-10-31 08:39:54 ----A---- C:\ComboFix.txt
2012-10-31 08:38:40 ----SHD---- C:\$RECYCLE.BIN
2012-10-31 08:26:01 ----D---- C:\ComboFix
2012-10-30 18:37:31 ----A---- C:\Windows\system32\mshtmled.dll
2012-10-30 18:37:30 ----A---- C:\Windows\system32\vbscript.dll
2012-10-30 18:37:30 ----A---- C:\Windows\system32\ieui.dll
2012-10-30 18:37:29 ----A---- C:\Windows\system32\jsproxy.dll
2012-10-30 18:37:29 ----A---- C:\Windows\system32\ieUnatt.exe
2012-10-30 18:37:28 ----A---- C:\Windows\system32\msfeeds.dll
2012-10-30 18:37:27 ----A---- C:\Windows\system32\wininet.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\url.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\jscript9.dll
2012-10-30 18:37:26 ----A---- C:\Windows\system32\jscript.dll
2012-10-30 18:37:24 ----A---- C:\Windows\system32\iertutil.dll
2012-10-30 18:37:23 ----A---- C:\Windows\system32\urlmon.dll
2012-10-30 18:37:21 ----A---- C:\Windows\system32\ieframe.dll
2012-10-30 18:37:20 ----A---- C:\Windows\system32\mshtml.dll
2012-10-30 18:20:50 ----A---- C:\Windows\system32\crypt32.dll
2012-10-30 18:20:49 ----A---- C:\Windows\system32\cryptsvc.dll
2012-10-30 18:20:49 ----A---- C:\Windows\system32\cryptnet.dll
2012-10-30 18:20:40 ----A---- C:\Windows\system32\localspl.dll
2012-10-30 18:20:36 ----A---- C:\Windows\system32\wintrust.dll
2012-10-30 18:20:33 ----A---- C:\Windows\system32\netapi32.dll
2012-10-30 18:20:32 ----A---- C:\Windows\system32\win32k.sys
2012-10-30 18:19:20 ----A---- C:\Windows\system32\tzres.dll
2012-10-30 18:18:41 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-10-30 18:18:40 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-10-29 09:03:58 ----D---- C:\Program Files\Mozilla Firefox
======List of files/folders modified in the last 1 month======
2012-10-31 09:07:42 ----D---- C:\Program Files\Trend Micro
2012-10-31 08:54:43 ----D---- C:\Windows\system32\drivers
2012-10-31 08:39:56 ----D---- C:\Qoobox
2012-10-31 08:39:55 ----D---- C:\Windows
2012-10-31 08:37:35 ----A---- C:\Windows\system.ini
2012-10-31 08:36:41 ----D---- C:\ProgramData
2012-10-31 08:33:01 ----D---- C:\Windows\System32
2012-10-31 08:33:01 ----D---- C:\Windows\AppPatch
2012-10-31 08:32:58 ----D---- C:\Program Files\Common Files
2012-10-31 08:19:05 ----D---- C:\Windows\Prefetch
2012-10-31 07:45:27 ----SHD---- C:\Windows\Installer
2012-10-31 07:42:03 ----D---- C:\Users\johny\AppData\Roaming\Skype
2012-10-31 07:41:55 ----D---- C:\ProgramData\Skype
2012-10-31 07:41:29 ----RD---- C:\Program Files\Skype
2012-10-31 07:40:56 ----D---- C:\Windows\inf
2012-10-31 07:40:56 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-10-31 07:39:12 ----SHD---- C:\System Volume Information
2012-10-31 07:34:20 ----D---- C:\Logs
2012-10-30 19:37:46 ----D---- C:\Windows\rescache
2012-10-30 19:31:12 ----D---- C:\Users\johny\AppData\Roaming\Winamp
2012-10-30 19:31:12 ----D---- C:\Users\johny\AppData\Roaming\DAEMON Tools Lite
2012-10-30 19:31:11 ----D---- C:\Windows\Debug
2012-10-30 19:12:34 ----D---- C:\Windows\system32\sk-SK
2012-10-30 19:12:34 ----D---- C:\Windows\system32\migration
2012-10-30 19:12:34 ----D---- C:\Program Files\Internet Explorer
2012-10-30 18:37:55 ----D---- C:\Windows\winsxs
2012-10-30 18:37:52 ----D---- C:\Windows\system32\catroot
2012-10-30 18:37:51 ----D---- C:\Windows\system32\catroot2
2012-10-30 11:15:42 ----D---- C:\ProgramData\PMB Files
2012-10-30 10:01:58 ----D---- C:\Program Files\Mozilla Maintenance Service
2012-10-29 12:16:26 ----RD---- C:\Program Files
2012-10-28 17:00:28 ----D---- C:\Windows\system32\Tasks
2012-10-23 12:17:38 ----A---- C:\Windows\system32\aswBoot.exe
2012-10-20 11:19:29 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-19 19:22:24 ----RSD---- C:\Windows\Fonts
2012-10-11 11:51:30 ----D---- C:\Windows\Minidump
2012-10-09 18:43:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AlfaFF;AlfaFF File System mini-filter; C:\Windows\system32\Drivers\AlfaFF.sys [2009-01-09 43184]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-07-20 324120]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-03-04 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-04 691696]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-30 13824]
R1 AswRdr;aswRdr; C:\Windows\system32\drivers\AswRdr.sys [2012-10-23 35928]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-23 738504]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-23 360392]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-23 54232]
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys [2007-01-24 67584]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-05-09 61424]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-23 21256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-23 58680]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-02-01 279712]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2007-01-26 69632]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-02-01 25888]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-03-04 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-03-04 60464]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (SwipeSensor); C:\Windows\system32\DRIVERS\ATSwpDrv.sys [2008-04-25 146688]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
R3 catchme;catchme; \??\C:\Users\johny\AppData\Local\Temp\catchme.sys []
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2008-07-02 21264]
R3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
R3 genmcmnUSB;USB Scroll Mouse Driver; C:\Windows\system32\DRIVERS\gflmouhid.sys [2004-04-19 6656]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-28 2127512]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-04-21 81296]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2010-11-12 122984]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-05-15 11354944]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-01-18 196784]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winbondcir;Winbond IR Transceiver; C:\Windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 22856]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 15048]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 66632]
S1 prodrv03;Star Force copy protection driver v3; C:\Windows\System32\drivers\prodrv03.sys [2009-01-13 115968]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys []
S3 aipad11g;aipad11g; C:\Windows\system32\drivers\aipad11g.sys []
S3 aura6dd0;aura6dd0; C:\Windows\system32\drivers\aura6dd0.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 CFcatchme;CFcatchme; \??\C:\Users\johny\AppData\Local\Temp\CFcatchme.sys []
S3 cimo;cimo; \??\C:\Windows\system32\cimo.sys [2009-08-05 51200]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\Users\johny\AppData\Local\Temp\DRYD6E2.tmp []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2010-12-30 15600]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 Maplom;Maplom; C:\Windows\system32\drivers\Maplom.sys []
S3 mbr;mbr; \??\C:\ComboFix\mbr.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster\Driver\WinRing0.sys [2010-11-01 14416]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\WinUSB.SYS [2009-04-11 31616]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 37704]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\Windows\system32\drivers\WmHidLo.sys [2010-04-27 31816]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-23 44808]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-03-04 500784]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2008-10-16 860160]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2008-07-20 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 645440]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2008-10-16 466944]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\Cyberlink\Shared files\RichVideo.exe [2007-01-09 272024]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 GJService;Game Jackal Server; C:\ProgramData\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe [2010-04-16 2031040]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2012-08-29 1385896]
S2 IGBASVC;iGroupTec Service; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [2009-01-09 3471360]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-07-13 160944]
S2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-16 135664]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 KFJZNW;KFJZNW; C:\Users\johny\AppData\Local\Temp\KFJZNW.exe []
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-29 115168]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 VECJ;VECJ; C:\Users\johny\AppData\Local\Temp\VECJ.exe []
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
-----------------EOF-----------------
Re: Pravdepodobne infikovaný notebook. (RSIT log)
Zdravim
Cetl jste si pravidla fora a dalsi veci ohledne CF - je jasne psano ze se nema spoustet bez doporuceni
Co se tyce ComboFixu, tak na zaklade licence a pravidel fora ptam, umite s nim pracovat (spusteni, rozlusteni logu, napsani skriptu)?
licencni podminky hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"

Nebezpeci CFka







- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
Re: Pravdepodobne infikovaný notebook. (RSIT log)
Ups, no ospravedlňujem sa.
Dávnejšie som mal tiež problém a vtedy pomocou Combo chceli log, tak som ho aj teraz použil. Ale potom som videl že RSIT tak som stiahol a použil ho.

Re: Pravdepodobne infikovaný notebook. (RSIT log)


Re: Pravdepodobne infikovaný notebook. (RSIT log)
ComboFix 12-10-30.03 - johny . 10. 2012 8:28.9.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3066.1997 [GMT 1:00]
Running from: c:\users\johny\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Files Created from 2012-09-28 to 2012-10-31 )))))))))))))))))))))))))))))))
.
.
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\johny\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-30 17:28 . 2012-10-17 01:32 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{123BF0BB-B314-4AD1-8F31-083690C0A578}\mpengine.dll
2012-10-30 17:20 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-30 17:20 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-30 17:20 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-30 17:20 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-10-30 17:20 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-30 17:20 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-10-30 17:19 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-30 17:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-30 17:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-23 11:18 . 2012-05-06 12:40 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-23 11:18 . 2012-05-06 12:40 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-23 11:18 . 2012-05-06 12:40 360392 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-23 11:18 . 2012-05-06 12:40 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-23 11:18 . 2012-05-06 12:40 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-23 11:18 . 2012-05-06 12:40 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-23 11:17 . 2012-05-06 12:39 41224 ----a-w- c:\windows\avastSS.scr
2012-10-23 11:17 . 2012-05-06 12:39 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-09 17:43 . 2012-05-19 07:56 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 17:43 . 2011-05-24 05:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-29 08:04 . 2012-10-29 08:03 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-03-17 13:45 2355224 ----a-w- c:\program files\Softonic-Eng7\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 11:17 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-23 397312]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-02 821768]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3607040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-05-12 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-05-12 167936]
"mouseElf"="c:\progra~1\TWINTO~1\MouseElf.EXE" [2004-08-26 192512]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-08-29 1996200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 18:04 2972160 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-06 20:42 34040 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
2008-03-07 01:36 544768 ----a-w- c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-08-29 10:03 1996200 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 17:43]
.
2012-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-10-30 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:07]
.
2012-10-31 c:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-25 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-26 c:\windows\Tasks\RegCure Pro.job
- c:\program files\ParetoLogic\RegCure Pro\RegCurePro.exe [2012-08-27 20:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.crawler.com/homepage.aspx?tbid=60347
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &U????????? - c:\program files\NamiRobot\Data\du.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - ExtSQL: !HIDDEN! 2009-12-04 21:26; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-SpywareTerminatorUpdate - c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-31 08:37
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\johny\AppData\Local\Temp\DRYD6E2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3212)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
Completion time: 2012-10-31 08:39:53
ComboFix-quarantined-files.txt 2012-10-31 07:39
ComboFix2.txt 2012-02-26 19:06
ComboFix3.txt 2012-02-26 17:30
ComboFix4.txt 2011-08-07 09:24
ComboFix5.txt 2012-10-31 07:26
.
Pre-Run: 76 052 070 400 bytes free
Post-Run: 75 730 808 832 bytes free
.
- - End Of File - - D61CBCF1F6732C8AFE6B998D5BA4B24F
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3066.1997 [GMT 1:00]
Running from: c:\users\johny\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
((((((((((((((((((((((((( Files Created from 2012-09-28 to 2012-10-31 )))))))))))))))))))))))))))))))
.
.
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\johny\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-10-31 07:37 . 2012-10-31 07:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-30 17:28 . 2012-10-17 01:32 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{123BF0BB-B314-4AD1-8F31-083690C0A578}\mpengine.dll
2012-10-30 17:20 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-30 17:20 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-30 17:20 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-30 17:20 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-10-30 17:20 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-30 17:20 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-10-30 17:19 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-30 17:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-30 17:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-23 11:18 . 2012-05-06 12:40 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-23 11:18 . 2012-05-06 12:40 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-23 11:18 . 2012-05-06 12:40 360392 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-23 11:18 . 2012-05-06 12:40 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-23 11:18 . 2012-05-06 12:40 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-23 11:18 . 2012-05-06 12:40 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-23 11:17 . 2012-05-06 12:39 41224 ----a-w- c:\windows\avastSS.scr
2012-10-23 11:17 . 2012-05-06 12:39 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-09 17:43 . 2012-05-19 07:56 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 17:43 . 2011-05-24 05:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-29 08:04 . 2012-10-29 08:03 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2010-03-17 13:45 2355224 ----a-w- c:\program files\Softonic-Eng7\tbSoft.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"= "c:\program files\Softonic-Eng7\tbSoft.dll" [2010-03-17 2355224]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 11:17 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-23 397312]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-02 821768]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3607040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-05-12 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-05-12 167936]
"mouseElf"="c:\progra~1\TWINTO~1\MouseElf.EXE" [2004-08-26 192512]
"Startup Cleaner"="c:\program files\CM Data Software\CM DiskCleaner\Startup Cleaner.exe" [2006-07-14 118784]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-08-29 1996200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 18:04 2972160 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-06 20:42 34040 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
2008-03-07 01:36 544768 ----a-w- c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-08-29 10:03 1996200 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 17:43]
.
2012-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-10-30 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:07]
.
2012-10-31 c:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-25 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-26 c:\windows\Tasks\RegCure Pro.job
- c:\program files\ParetoLogic\RegCure Pro\RegCurePro.exe [2012-08-27 20:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.crawler.com/homepage.aspx?tbid=60347
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &U????????? - c:\program files\NamiRobot\Data\du.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - ExtSQL: !HIDDEN! 2009-12-04 21:26; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-SpywareTerminatorUpdate - c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-31 08:37
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\johny\AppData\Local\Temp\DRYD6E2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3212)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
Completion time: 2012-10-31 08:39:53
ComboFix-quarantined-files.txt 2012-10-31 07:39
ComboFix2.txt 2012-02-26 19:06
ComboFix3.txt 2012-02-26 17:30
ComboFix4.txt 2011-08-07 09:24
ComboFix5.txt 2012-10-31 07:26
.
Pre-Run: 76 052 070 400 bytes free
Post-Run: 75 730 808 832 bytes free
.
- - End Of File - - D61CBCF1F6732C8AFE6B998D5BA4B24F
Re: Pravdepodobne infikovaný notebook. (RSIT log)



Re: Pravdepodobne infikovaný notebook. (RSIT log)
A on bezel hodinu
Ja bych rekl ze dneska 2x dle logu...

Re: Pravdepodobne infikovaný notebook. (RSIT log)
Koľko šiel to neviem, ale sa updatoval tak asi preto je v logu že sa dvakrát zapol.
Re: Pravdepodobne infikovaný notebook. (RSIT log)

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Search
- Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte
Re: Pravdepodobne infikovaný notebook. (RSIT log)
# AdwCleaner v2.006 - Logfile created 10/31/2012 at 13:43:13
# Updated 30/10/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : johny - MOJPC
# Boot Mode : Normal
# Running from : C:\Users\johny\Desktop\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Askcom.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Conduit.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\daemon-search.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-3.xml
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\Softonic-Eng7
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Premium
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\Users\johny\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\johny\AppData\LocalLow\Conduit
Folder Found : C:\Users\johny\AppData\LocalLow\ConduitEngine
Folder Found : C:\Users\johny\AppData\LocalLow\free-downloads.net
Folder Found : C:\Users\johny\AppData\LocalLow\Softonic-Eng7
Folder Found : C:\Users\johny\AppData\Roaming\iWin
Folder Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\Conduit
Folder Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\ConduitEngine
Folder Found : C:\Users\johny\AppData\Roaming\OpenCandy
***** [Registry] *****
Key Found : HKCU\Software\AppDataLow\Software
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\free-downloads.net
Key Found : HKCU\Software\AppDataLow\Software\Softonic-Eng7
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CToolbar_UNINSTALL
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-Eng7 Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{588F6892-E562-42BB-AE46-1400E5EBE913}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B2D230B5-FDDB-4102-BE68-4DB7ABD30EBD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2304157
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2405280
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\conduitEngine
Key Found : HKLM\Software\conduitEngine
Key Found : HKLM\Software\free-downloads.net
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAA9C7B9-73E7-44E7-A0B2-7B7D7EFDC4FE}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-Eng7 Toolbar
Key Found : HKLM\Software\Softonic-Eng7
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{ECDEE021-0D17-467F-A1FF-C7A115230949}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - SearchAssistant] = hxxp://www.crawler.com/search/ie.aspx?tb_id=60347
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - CustomizeSearch] = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.crawler.com/homepage.aspx?tbid=60347
[HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\prefs.js
Found : user_pref("CT2405280..clientLogIsEnabled", true);
Found : user_pref("CT2405280..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2405280..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2405280.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2405280.CTID", "CT2405280");
Found : user_pref("CT2405280.CurrentServerDate", "16-7-2011");
Found : user_pref("CT2405280.DialogsAlignMode", "LTR");
Found : user_pref("CT2405280.DialogsGetterLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.DownloadReferralCookieData", "");
Found : user_pref("CT2405280.EMailNotifierPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedLastCount1783261708582779529", 702);
Found : user_pref("CT2405280.FeedPollDate129212394466815234", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815240", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815246", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815252", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815258", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815264", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815270", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815276", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815282", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815288", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815294", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815300", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815306", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815312", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971568", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971574", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971580", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971586", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971592", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971598", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971604", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971610", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971616", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971622", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971628", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971634", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971640", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971646", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971652", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971658", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971664", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971670", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971676", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971682", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971688", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971694", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971700", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971706", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127962", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127968", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127974", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127980", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127986", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127992", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127998", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128004", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128010", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128016", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128022", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128028", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128034", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128040", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedTTL129212394466815246", 15);
Found : user_pref("CT2405280.FeedTTL129212394466815258", 60);
Found : user_pref("CT2405280.FeedTTL129212394466815264", 10);
Found : user_pref("CT2405280.FeedTTL129212394466815312", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971568", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971574", 2);
Found : user_pref("CT2405280.FeedTTL129212394466971580", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971592", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971598", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971604", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971616", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971628", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971634", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971640", 2);
Found : user_pref("CT2405280.FeedTTL129212394466971658", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971670", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971676", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971682", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971700", 1440);
Found : user_pref("CT2405280.FeedTTL129212394467127980", 10);
Found : user_pref("CT2405280.FeedTTL129212394467127998", 5);
Found : user_pref("CT2405280.FirstServerDate", "14-7-2010");
Found : user_pref("CT2405280.FirstTime", true);
Found : user_pref("CT2405280.FirstTimeFF3", true);
Found : user_pref("CT2405280.FirstTimeSettingsDone", true);
Found : user_pref("CT2405280.FixPageNotFoundErrors", true);
Found : user_pref("CT2405280.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2405280.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2405280.Initialize", true);
Found : user_pref("CT2405280.InitializeCommonPrefs", true);
Found : user_pref("CT2405280.InstallationAndCookieDataSentCount", 2);
Found : user_pref("CT2405280.InstalledDate", "Wed Jul 14 2010 17:21:39 GMT+0200");
Found : user_pref("CT2405280.InvalidateCache", false);
Found : user_pref("CT2405280.IsGrouping", false);
Found : user_pref("CT2405280.IsOpenThankYouPage", false);
Found : user_pref("CT2405280.IsOpenUninstallPage", true);
Found : user_pref("CT2405280.LanguagePackLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2405280.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2405280.LastLogin_2.7.1.3", "Wed Jul 14 2010 17:21:40 GMT+0200");
Found : user_pref("CT2405280.LastLogin_3.3.3.2", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.LatestVersion", "3.3.3.2");
Found : user_pref("CT2405280.Locale", "en-us");
Found : user_pref("CT2405280.LoginCache", 4);
Found : user_pref("CT2405280.MCDetectTooltipHeight", "83");
Found : user_pref("CT2405280.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2405280.MCDetectTooltipWidth", "295");
Found : user_pref("CT2405280.RadioIsPodcast", false);
Found : user_pref("CT2405280.RadioLastCheckTime", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2405280.RadioLastUpdateServer", "129167775315800000");
Found : user_pref("CT2405280.RadioMediaID", "20503713");
Found : user_pref("CT2405280.RadioMediaType", "Media Player");
Found : user_pref("CT2405280.RadioMenuSelectedID", "EBRadioMenu_CT240528020503713");
Found : user_pref("CT2405280.RadioStationName", "Virgin%20Radio%20Classic%20Rock");
Found : user_pref("CT2405280.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[...]
Found : user_pref("CT2405280.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2405280.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2405280.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2405280.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[...]
Found : user_pref("CT2405280.SearchInNewTabEnabled", true);
Found : user_pref("CT2405280.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2405280.SearchInNewTabLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2405280.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2405280.ServiceMapLastCheckTime", "Sat Jul 16 2011 21:34:25 GMT+0200");
Found : user_pref("CT2405280.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2405280.SettingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Found : user_pref("CT2405280.SettingsLastUpdate", "1309334663");
Found : user_pref("CT2405280.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2405280.ThirdPartyComponentsLastCheck", "Sat Jul 16 2011 21:34:25 GMT+0200");
Found : user_pref("CT2405280.ThirdPartyComponentsLastUpdate", "1279117606");
Found : user_pref("CT2405280.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2405280");
Found : user_pref("CT2405280.UserID", "UN18001454394874772");
Found : user_pref("CT2405280.WeatherNetwork", "");
Found : user_pref("CT2405280.WeatherPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.WeatherUnit", "C");
Found : user_pref("CT2405280.alertChannelId", "799768");
Found : user_pref("CT2405280.clientLogIsEnabled", false);
Found : user_pref("CT2405280.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2405280.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Found : user_pref("CT2405280.globalFirstTimeInfoLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.isAppTrackingManagerOn", true);
Found : user_pref("CT2405280.myStuffEnabled", true);
Found : user_pref("CT2405280.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2405280.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2405280.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2405280.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2405280.toolbarAppMetaDataLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.toolbarContextMenuLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CT2438727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2438727.CTID", "CT2438727");
Found : user_pref("CT2438727.CommunitiesChangesLastCheckTime", "0");
Found : user_pref("CT2438727.CurrentServerDate", "10-1-2011");
Found : user_pref("CT2438727.DialogsAlignMode", "LTR");
Found : user_pref("CT2438727.DownloadReferralCookieData", "");
Found : user_pref("CT2438727.EMailNotifierPollDate", "Sun Oct 17 2010 18:01:56 GMT+0200");
Found : user_pref("CT2438727.FirstServerDate", "14-7-2010");
Found : user_pref("CT2438727.FirstTime", true);
Found : user_pref("CT2438727.FirstTimeFF3", true);
Found : user_pref("CT2438727.FirstTimeSettingsDone", true);
Found : user_pref("CT2438727.FixPageNotFoundErrors", true);
Found : user_pref("CT2438727.GroupingInvalidateCache", false);
Found : user_pref("CT2438727.GroupingLastCheckTime", "0");
Found : user_pref("CT2438727.GroupingLastServerUpdateTime", "0");
Found : user_pref("CT2438727.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2438727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2438727.Initialize", true);
Found : user_pref("CT2438727.InitializeCommonPrefs", true);
Found : user_pref("CT2438727.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2438727.InstalledDate", "Wed Jul 14 2010 16:23:14 GMT+0200");
Found : user_pref("CT2438727.InvalidateCache", false);
Found : user_pref("CT2438727.IsGrouping", false);
Found : user_pref("CT2438727.IsMulticommunity", false);
Found : user_pref("CT2438727.IsOpenThankYouPage", true);
Found : user_pref("CT2438727.IsOpenUninstallPage", true);
Found : user_pref("CT2438727.LanguagePackLastCheckTime", "Mon Jan 10 2011 14:07:45 GMT+0100");
Found : user_pref("CT2438727.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2438727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2438727.LastLogin_2.7.1.3", "Mon Jan 10 2011 18:08:15 GMT+0100");
Found : user_pref("CT2438727.LatestVersion", "2.7.1.3");
Found : user_pref("CT2438727.Locale", "en");
Found : user_pref("CT2438727.LoginCache", 4);
Found : user_pref("CT2438727.MCDetectTooltipHeight", "83");
Found : user_pref("CT2438727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2438727.MCDetectTooltipWidth", "295");
Found : user_pref("CT2438727.RadioIsPodcast", false);
Found : user_pref("CT2438727.RadioLastCheckTime", "Sun Oct 17 2010 12:59:33 GMT+0200");
Found : user_pref("CT2438727.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2438727.RadioLastUpdateServer", "0");
Found : user_pref("CT2438727.RadioMediaID", "9962");
Found : user_pref("CT2438727.RadioMediaType", "Media Player");
Found : user_pref("CT2438727.RadioMenuSelectedID", "EBRadioMenu_CT24387279962");
Found : user_pref("CT2438727.RadioStationName", "California%20Rock");
Found : user_pref("CT2438727.RadioStationURL", "hxxp://feedlive.net/california.asx");
Found : user_pref("CT2438727.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2438727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2438727.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2438727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Found : user_pref("CT2438727.SearchInNewTabEnabled", true);
Found : user_pref("CT2438727.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2438727.SearchInNewTabLastCheckTime", "Mon Jan 10 2011 14:07:44 GMT+0100");
Found : user_pref("CT2438727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2438727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2438727.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2438727.SettingsLastCheckTime", "Mon Jan 10 2011 16:32:28 GMT+0100");
Found : user_pref("CT2438727.SettingsLastUpdate", "1287517459");
Found : user_pref("CT2438727.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2438727.ThirdPartyComponentsLastCheck", "Sat Jan 08 2011 00:14:36 GMT+0100");
Found : user_pref("CT2438727.ThirdPartyComponentsLastUpdate", "1278548974");
Found : user_pref("CT2438727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Found : user_pref("CT2438727.UserID", "UN61348303777439454");
Found : user_pref("CT2438727.ValidationData_Toolbar", 2);
Found : user_pref("CT2438727.WeatherNetwork", "");
Found : user_pref("CT2438727.WeatherPollDate", "Sun Oct 17 2010 18:01:57 GMT+0200");
Found : user_pref("CT2438727.WeatherUnit", "C");
Found : user_pref("CT2438727.alertChannelId", "832836");
Found : user_pref("CT2438727.clientLogIsEnabled", true);
Found : user_pref("CT2438727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2438727.myStuffEnabled", true);
Found : user_pref("CT2438727.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2438727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2438727.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2438727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2438727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CT2786678..clientLogIsEnabled", true);
Found : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2786678.CTID", "CT2786678");
Found : user_pref("CT2786678.CurrentServerDate", "29-4-2011");
Found : user_pref("CT2786678.DialogsAlignMode", "LTR");
Found : user_pref("CT2786678.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:48 GMT+0200");
Found : user_pref("CT2786678.DownloadReferralCookieData", "");
Found : user_pref("CT2786678.EMailNotifierPollDate", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedLastCount5690698542593514850", 185);
Found : user_pref("CT2786678.FeedPollDate129301619375443753", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375443759", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444699", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444705", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444711", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444717", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444723", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444729", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444735", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444741", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444747", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedTTL129301619375444699", 10);
Found : user_pref("CT2786678.FeedTTL129301619375444723", 15);
Found : user_pref("CT2786678.FeedTTL129301619375444735", 5);
Found : user_pref("CT2786678.FeedTTL129301619375444747", 5);
Found : user_pref("CT2786678.FirstServerDate", "29-4-2011");
Found : user_pref("CT2786678.FirstTime", true);
Found : user_pref("CT2786678.FirstTimeFF3", true);
Found : user_pref("CT2786678.FixPageNotFoundErrors", false);
Found : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2786678.HasUserGlobalKeys", true);
Found : user_pref("CT2786678.Initialize", true);
Found : user_pref("CT2786678.InitializeCommonPrefs", true);
Found : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1);
Found : user_pref("CT2786678.InstallationType", "UnknownIntegration");
Found : user_pref("CT2786678.InstalledDate", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("CT2786678.IsGrouping", false);
Found : user_pref("CT2786678.IsMulticommunity", false);
Found : user_pref("CT2786678.IsOpenThankYouPage", true);
Found : user_pref("CT2786678.IsOpenUninstallPage", false);
Found : user_pref("CT2786678.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:47 GMT+0200");
Found : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2786678.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:40 GMT+0200");
Found : user_pref("CT2786678.LatestVersion", "3.3.3.2");
Found : user_pref("CT2786678.Locale", "en");
Found : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Found : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Found : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Found : user_pref("CT2786678.SearchInNewTabEnabled", true);
Found : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Fri Apr 29 2011 16:01:40 GMT+0200");
Found : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2786678.ServiceMapLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.SettingsLastUpdate", "1297856274");
Found : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246786978");
Found : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
Found : user_pref("CT2786678.UserID", "UN53507959899756299");
Found : user_pref("CT2786678.WeatherNetwork", "");
Found : user_pref("CT2786678.WeatherPollDate", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.WeatherUnit", "C");
Found : user_pref("CT2786678.alertChannelId", "1178763");
Found : user_pref("CT2786678.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Found : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Found : user_pref("CT2786678.myStuffEnabled", true);
Found : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2786678.testingCtid", "");
Found : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+0200");
Found : user_pref("CT2786678.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/SK", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2405280", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=2.5.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2786678",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63443493058760[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2405280/CT2405280[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalize[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.EngineHiddenByUser", false);
Found : user_pref("CommunityToolbar.EngineOwner", "CT2786678");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar");
Found : user_pref("CommunityToolbar.IsEngineShown", false);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+02[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Feb 26 2012 11:49:11 GMT+0100");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Feb 26 2012 11:49:03 GMT+0100");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "6ee531ef-29d3-4d53-9122-9476f17ea0f2");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Found : user_pref("CommunityToolbar.globalUserId", "ce5141bd-5242-437a-bb41-b94434f4c833");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2304157");
Found : user_pref("CommunityToolbar.twitter.user_21817319.LastCheckTime", "Fri Feb 18 2011 17:16:30 GMT+0100[...]
Found : user_pref("ConduitEngine.CTID", "ConduitEngine");
Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:02:12 GMT+0200");
Found : user_pref("ConduitEngine.FirstServerDate", "04/29/2011 17");
Found : user_pref("ConduitEngine.FirstTime", true);
Found : user_pref("ConduitEngine.FirstTimeFF3", true);
Found : user_pref("ConduitEngine.FixPageNotFoundErrors", false);
Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Found : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Found : user_pref("ConduitEngine.Initialize", true);
Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Found : user_pref("ConduitEngine.InstallationType", "UnknownIntegration");
Found : user_pref("ConduitEngine.InstalledDate", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("ConduitEngine.IsMulticommunity", false);
Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Found : user_pref("ConduitEngine.IsOpenUninstallPage", false);
Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:41 GMT+0200");
Found : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Found : user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("ConduitEngine.UserID", "UN26450304765024135");
Found : user_pref("ConduitEngine.engineLocale", "cs");
Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Found : user_pref("ConduitEngine.initDone", true);
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultthis.engineName", "XfireXO Customized Web Search");
Found : user_pref("browser.search.order.1", "Crawler Search");
Found : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;media_btn_wa;shout_btn_wa;ai[...]
Found : user_pref("winamp_toolbar.firsttime.showwindow", false);
Found : user_pref("winamp_toolbar.install.lastTbVersion", "5.5.1.1");
Found : user_pref("winamp_toolbar.metrics.activestampdate", "17");
Found : user_pref("winamp_toolbar.metrics.activestampmonth", "10");
Found : user_pref("winamp_toolbar.metrics.activestampyear", "2009");
Found : user_pref("winamp_toolbar.metrics.originalDate", "9");
Found : user_pref("winamp_toolbar.metrics.originalHours", "9");
Found : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Found : user_pref("winamp_toolbar.metrics.originalMonth", "1");
Found : user_pref("winamp_toolbar.metrics.originalSeconds", "21");
Found : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Found : user_pref("winamp_toolbar.search.populateoncomplete", false);
Found : user_pref("winamp_toolbar.search.searchtype", "web");
Found : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Found : user_pref("winamp_toolbar.upgrade.showwindow", false);
Found : user_pref("winamp_toolbar.winamp.artist", "");
Found : user_pref("winamp_toolbar.winamp.title", "-999999");
Found : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Found : user_pref("winamp_toolbar.winamp.tracktime", "-999998");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\johny\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [42371 octets] - [31/10/2012 13:43:13]
########## EOF - C:\AdwCleaner[R1].txt - [42432 octets] ##########
# Updated 30/10/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : johny - MOJPC
# Boot Mode : Normal
# Running from : C:\Users\johny\Desktop\adwcleaner.exe
# Option [Search]
***** [Services] *****
***** [Files / Folders] *****
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Askcom.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Conduit.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\daemon-search.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-3.xml
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\Softonic-Eng7
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Premium
Folder Found : C:\ProgramData\Trymedia
Folder Found : C:\Users\johny\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\johny\AppData\LocalLow\Conduit
Folder Found : C:\Users\johny\AppData\LocalLow\ConduitEngine
Folder Found : C:\Users\johny\AppData\LocalLow\free-downloads.net
Folder Found : C:\Users\johny\AppData\LocalLow\Softonic-Eng7
Folder Found : C:\Users\johny\AppData\Roaming\iWin
Folder Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\Conduit
Folder Found : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\ConduitEngine
Folder Found : C:\Users\johny\AppData\Roaming\OpenCandy
***** [Registry] *****
Key Found : HKCU\Software\AppDataLow\Software
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
Key Found : HKCU\Software\AppDataLow\Software\free-downloads.net
Key Found : HKCU\Software\AppDataLow\Software\Softonic-Eng7
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CToolbar_UNINSTALL
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-Eng7 Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{588F6892-E562-42BB-AE46-1400E5EBE913}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B2D230B5-FDDB-4102-BE68-4DB7ABD30EBD}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2304157
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2405280
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\conduitEngine
Key Found : HKLM\Software\conduitEngine
Key Found : HKLM\Software\free-downloads.net
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAA9C7B9-73E7-44E7-A0B2-7B7D7EFDC4FE}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-Eng7 Toolbar
Key Found : HKLM\Software\Softonic-Eng7
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Found : HKU\S-1-5-21-3966806968-2824471673-2848729136-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{ECDEE021-0D17-467F-A1FF-C7A115230949}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - SearchAssistant] = hxxp://www.crawler.com/search/ie.aspx?tb_id=60347
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - CustomizeSearch] = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.crawler.com/homepage.aspx?tbid=60347
[HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\prefs.js
Found : user_pref("CT2405280..clientLogIsEnabled", true);
Found : user_pref("CT2405280..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2405280..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2405280.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2405280.CTID", "CT2405280");
Found : user_pref("CT2405280.CurrentServerDate", "16-7-2011");
Found : user_pref("CT2405280.DialogsAlignMode", "LTR");
Found : user_pref("CT2405280.DialogsGetterLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.DownloadReferralCookieData", "");
Found : user_pref("CT2405280.EMailNotifierPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedLastCount1783261708582779529", 702);
Found : user_pref("CT2405280.FeedPollDate129212394466815234", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815240", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815246", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815252", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815258", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815264", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815270", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815276", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815282", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815288", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815294", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815300", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815306", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466815312", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971568", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971574", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971580", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971586", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971592", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971598", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971604", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971610", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971616", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971622", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971628", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971634", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971640", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971646", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971652", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971658", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971664", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971670", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971676", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971682", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971688", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971694", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971700", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394466971706", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127962", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127968", "Sat Jul 16 2011 21:34:30 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127974", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127980", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127986", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127992", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467127998", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128004", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128010", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128016", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128022", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128028", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128034", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedPollDate129212394467128040", "Sat Jul 16 2011 21:34:31 GMT+0200");
Found : user_pref("CT2405280.FeedTTL129212394466815246", 15);
Found : user_pref("CT2405280.FeedTTL129212394466815258", 60);
Found : user_pref("CT2405280.FeedTTL129212394466815264", 10);
Found : user_pref("CT2405280.FeedTTL129212394466815312", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971568", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971574", 2);
Found : user_pref("CT2405280.FeedTTL129212394466971580", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971592", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971598", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971604", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971616", 5);
Found : user_pref("CT2405280.FeedTTL129212394466971628", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971634", 30);
Found : user_pref("CT2405280.FeedTTL129212394466971640", 2);
Found : user_pref("CT2405280.FeedTTL129212394466971658", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971670", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971676", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971682", 15);
Found : user_pref("CT2405280.FeedTTL129212394466971700", 1440);
Found : user_pref("CT2405280.FeedTTL129212394467127980", 10);
Found : user_pref("CT2405280.FeedTTL129212394467127998", 5);
Found : user_pref("CT2405280.FirstServerDate", "14-7-2010");
Found : user_pref("CT2405280.FirstTime", true);
Found : user_pref("CT2405280.FirstTimeFF3", true);
Found : user_pref("CT2405280.FirstTimeSettingsDone", true);
Found : user_pref("CT2405280.FixPageNotFoundErrors", true);
Found : user_pref("CT2405280.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2405280.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2405280.Initialize", true);
Found : user_pref("CT2405280.InitializeCommonPrefs", true);
Found : user_pref("CT2405280.InstallationAndCookieDataSentCount", 2);
Found : user_pref("CT2405280.InstalledDate", "Wed Jul 14 2010 17:21:39 GMT+0200");
Found : user_pref("CT2405280.InvalidateCache", false);
Found : user_pref("CT2405280.IsGrouping", false);
Found : user_pref("CT2405280.IsOpenThankYouPage", false);
Found : user_pref("CT2405280.IsOpenUninstallPage", true);
Found : user_pref("CT2405280.LanguagePackLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2405280.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2405280.LastLogin_2.7.1.3", "Wed Jul 14 2010 17:21:40 GMT+0200");
Found : user_pref("CT2405280.LastLogin_3.3.3.2", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.LatestVersion", "3.3.3.2");
Found : user_pref("CT2405280.Locale", "en-us");
Found : user_pref("CT2405280.LoginCache", 4);
Found : user_pref("CT2405280.MCDetectTooltipHeight", "83");
Found : user_pref("CT2405280.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2405280.MCDetectTooltipWidth", "295");
Found : user_pref("CT2405280.RadioIsPodcast", false);
Found : user_pref("CT2405280.RadioLastCheckTime", "Sat Jul 16 2011 21:34:27 GMT+0200");
Found : user_pref("CT2405280.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2405280.RadioLastUpdateServer", "129167775315800000");
Found : user_pref("CT2405280.RadioMediaID", "20503713");
Found : user_pref("CT2405280.RadioMediaType", "Media Player");
Found : user_pref("CT2405280.RadioMenuSelectedID", "EBRadioMenu_CT240528020503713");
Found : user_pref("CT2405280.RadioStationName", "Virgin%20Radio%20Classic%20Rock");
Found : user_pref("CT2405280.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[...]
Found : user_pref("CT2405280.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2405280.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2405280.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2405280.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[...]
Found : user_pref("CT2405280.SearchInNewTabEnabled", true);
Found : user_pref("CT2405280.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2405280.SearchInNewTabLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2405280.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2405280.ServiceMapLastCheckTime", "Sat Jul 16 2011 21:34:25 GMT+0200");
Found : user_pref("CT2405280.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2405280.SettingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Found : user_pref("CT2405280.SettingsLastUpdate", "1309334663");
Found : user_pref("CT2405280.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2405280.ThirdPartyComponentsLastCheck", "Sat Jul 16 2011 21:34:25 GMT+0200");
Found : user_pref("CT2405280.ThirdPartyComponentsLastUpdate", "1279117606");
Found : user_pref("CT2405280.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2405280");
Found : user_pref("CT2405280.UserID", "UN18001454394874772");
Found : user_pref("CT2405280.WeatherNetwork", "");
Found : user_pref("CT2405280.WeatherPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.WeatherUnit", "C");
Found : user_pref("CT2405280.alertChannelId", "799768");
Found : user_pref("CT2405280.clientLogIsEnabled", false);
Found : user_pref("CT2405280.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2405280.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Found : user_pref("CT2405280.globalFirstTimeInfoLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Found : user_pref("CT2405280.isAppTrackingManagerOn", true);
Found : user_pref("CT2405280.myStuffEnabled", true);
Found : user_pref("CT2405280.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2405280.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2405280.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2405280.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2405280.toolbarAppMetaDataLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.toolbarContextMenuLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Found : user_pref("CT2405280.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CT2438727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2438727.CTID", "CT2438727");
Found : user_pref("CT2438727.CommunitiesChangesLastCheckTime", "0");
Found : user_pref("CT2438727.CurrentServerDate", "10-1-2011");
Found : user_pref("CT2438727.DialogsAlignMode", "LTR");
Found : user_pref("CT2438727.DownloadReferralCookieData", "");
Found : user_pref("CT2438727.EMailNotifierPollDate", "Sun Oct 17 2010 18:01:56 GMT+0200");
Found : user_pref("CT2438727.FirstServerDate", "14-7-2010");
Found : user_pref("CT2438727.FirstTime", true);
Found : user_pref("CT2438727.FirstTimeFF3", true);
Found : user_pref("CT2438727.FirstTimeSettingsDone", true);
Found : user_pref("CT2438727.FixPageNotFoundErrors", true);
Found : user_pref("CT2438727.GroupingInvalidateCache", false);
Found : user_pref("CT2438727.GroupingLastCheckTime", "0");
Found : user_pref("CT2438727.GroupingLastServerUpdateTime", "0");
Found : user_pref("CT2438727.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2438727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2438727.Initialize", true);
Found : user_pref("CT2438727.InitializeCommonPrefs", true);
Found : user_pref("CT2438727.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2438727.InstalledDate", "Wed Jul 14 2010 16:23:14 GMT+0200");
Found : user_pref("CT2438727.InvalidateCache", false);
Found : user_pref("CT2438727.IsGrouping", false);
Found : user_pref("CT2438727.IsMulticommunity", false);
Found : user_pref("CT2438727.IsOpenThankYouPage", true);
Found : user_pref("CT2438727.IsOpenUninstallPage", true);
Found : user_pref("CT2438727.LanguagePackLastCheckTime", "Mon Jan 10 2011 14:07:45 GMT+0100");
Found : user_pref("CT2438727.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2438727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2438727.LastLogin_2.7.1.3", "Mon Jan 10 2011 18:08:15 GMT+0100");
Found : user_pref("CT2438727.LatestVersion", "2.7.1.3");
Found : user_pref("CT2438727.Locale", "en");
Found : user_pref("CT2438727.LoginCache", 4);
Found : user_pref("CT2438727.MCDetectTooltipHeight", "83");
Found : user_pref("CT2438727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2438727.MCDetectTooltipWidth", "295");
Found : user_pref("CT2438727.RadioIsPodcast", false);
Found : user_pref("CT2438727.RadioLastCheckTime", "Sun Oct 17 2010 12:59:33 GMT+0200");
Found : user_pref("CT2438727.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2438727.RadioLastUpdateServer", "0");
Found : user_pref("CT2438727.RadioMediaID", "9962");
Found : user_pref("CT2438727.RadioMediaType", "Media Player");
Found : user_pref("CT2438727.RadioMenuSelectedID", "EBRadioMenu_CT24387279962");
Found : user_pref("CT2438727.RadioStationName", "California%20Rock");
Found : user_pref("CT2438727.RadioStationURL", "hxxp://feedlive.net/california.asx");
Found : user_pref("CT2438727.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2438727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Found : user_pref("CT2438727.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2438727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Found : user_pref("CT2438727.SearchInNewTabEnabled", true);
Found : user_pref("CT2438727.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2438727.SearchInNewTabLastCheckTime", "Mon Jan 10 2011 14:07:44 GMT+0100");
Found : user_pref("CT2438727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2438727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2438727.SettingsCheckIntervalMin", 120);
Found : user_pref("CT2438727.SettingsLastCheckTime", "Mon Jan 10 2011 16:32:28 GMT+0100");
Found : user_pref("CT2438727.SettingsLastUpdate", "1287517459");
Found : user_pref("CT2438727.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2438727.ThirdPartyComponentsLastCheck", "Sat Jan 08 2011 00:14:36 GMT+0100");
Found : user_pref("CT2438727.ThirdPartyComponentsLastUpdate", "1278548974");
Found : user_pref("CT2438727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Found : user_pref("CT2438727.UserID", "UN61348303777439454");
Found : user_pref("CT2438727.ValidationData_Toolbar", 2);
Found : user_pref("CT2438727.WeatherNetwork", "");
Found : user_pref("CT2438727.WeatherPollDate", "Sun Oct 17 2010 18:01:57 GMT+0200");
Found : user_pref("CT2438727.WeatherUnit", "C");
Found : user_pref("CT2438727.alertChannelId", "832836");
Found : user_pref("CT2438727.clientLogIsEnabled", true);
Found : user_pref("CT2438727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Found : user_pref("CT2438727.myStuffEnabled", true);
Found : user_pref("CT2438727.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2438727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2438727.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2438727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2438727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Found : user_pref("CT2786678..clientLogIsEnabled", true);
Found : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2786678.CTID", "CT2786678");
Found : user_pref("CT2786678.CurrentServerDate", "29-4-2011");
Found : user_pref("CT2786678.DialogsAlignMode", "LTR");
Found : user_pref("CT2786678.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:48 GMT+0200");
Found : user_pref("CT2786678.DownloadReferralCookieData", "");
Found : user_pref("CT2786678.EMailNotifierPollDate", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedLastCount5690698542593514850", 185);
Found : user_pref("CT2786678.FeedPollDate129301619375443753", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375443759", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444699", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444705", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444711", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444717", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444723", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444729", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444735", "Fri Apr 29 2011 17:07:06 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444741", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedPollDate129301619375444747", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.FeedTTL129301619375444699", 10);
Found : user_pref("CT2786678.FeedTTL129301619375444723", 15);
Found : user_pref("CT2786678.FeedTTL129301619375444735", 5);
Found : user_pref("CT2786678.FeedTTL129301619375444747", 5);
Found : user_pref("CT2786678.FirstServerDate", "29-4-2011");
Found : user_pref("CT2786678.FirstTime", true);
Found : user_pref("CT2786678.FirstTimeFF3", true);
Found : user_pref("CT2786678.FixPageNotFoundErrors", false);
Found : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2786678.HasUserGlobalKeys", true);
Found : user_pref("CT2786678.Initialize", true);
Found : user_pref("CT2786678.InitializeCommonPrefs", true);
Found : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1);
Found : user_pref("CT2786678.InstallationType", "UnknownIntegration");
Found : user_pref("CT2786678.InstalledDate", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("CT2786678.IsGrouping", false);
Found : user_pref("CT2786678.IsMulticommunity", false);
Found : user_pref("CT2786678.IsOpenThankYouPage", true);
Found : user_pref("CT2786678.IsOpenUninstallPage", false);
Found : user_pref("CT2786678.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:47 GMT+0200");
Found : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2786678.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:40 GMT+0200");
Found : user_pref("CT2786678.LatestVersion", "3.3.3.2");
Found : user_pref("CT2786678.Locale", "en");
Found : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Found : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Found : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Found : user_pref("CT2786678.SearchInNewTabEnabled", true);
Found : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Fri Apr 29 2011 16:01:40 GMT+0200");
Found : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2786678.ServiceMapLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.SettingsLastUpdate", "1297856274");
Found : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246786978");
Found : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
Found : user_pref("CT2786678.UserID", "UN53507959899756299");
Found : user_pref("CT2786678.WeatherNetwork", "");
Found : user_pref("CT2786678.WeatherPollDate", "Fri Apr 29 2011 17:07:07 GMT+0200");
Found : user_pref("CT2786678.WeatherUnit", "C");
Found : user_pref("CT2786678.alertChannelId", "1178763");
Found : user_pref("CT2786678.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Found : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Found : user_pref("CT2786678.myStuffEnabled", true);
Found : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2786678.testingCtid", "");
Found : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+0200");
Found : user_pref("CT2786678.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/SK", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2405280", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=2.5.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2786678",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63443493058760[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2405280/CT2405280[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalize[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.EngineHiddenByUser", false);
Found : user_pref("CommunityToolbar.EngineOwner", "CT2786678");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar");
Found : user_pref("CommunityToolbar.IsEngineShown", false);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+02[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Feb 26 2012 11:49:11 GMT+0100");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Feb 26 2012 11:49:03 GMT+0100");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "6ee531ef-29d3-4d53-9122-9476f17ea0f2");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Found : user_pref("CommunityToolbar.globalUserId", "ce5141bd-5242-437a-bb41-b94434f4c833");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2304157");
Found : user_pref("CommunityToolbar.twitter.user_21817319.LastCheckTime", "Fri Feb 18 2011 17:16:30 GMT+0100[...]
Found : user_pref("ConduitEngine.CTID", "ConduitEngine");
Found : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:02:12 GMT+0200");
Found : user_pref("ConduitEngine.FirstServerDate", "04/29/2011 17");
Found : user_pref("ConduitEngine.FirstTime", true);
Found : user_pref("ConduitEngine.FirstTimeFF3", true);
Found : user_pref("ConduitEngine.FixPageNotFoundErrors", false);
Found : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Found : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Found : user_pref("ConduitEngine.Initialize", true);
Found : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Found : user_pref("ConduitEngine.InstallationType", "UnknownIntegration");
Found : user_pref("ConduitEngine.InstalledDate", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("ConduitEngine.IsMulticommunity", false);
Found : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Found : user_pref("ConduitEngine.IsOpenUninstallPage", false);
Found : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:41 GMT+0200");
Found : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Found : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Found : user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Found : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Found : user_pref("ConduitEngine.UserID", "UN26450304765024135");
Found : user_pref("ConduitEngine.engineLocale", "cs");
Found : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Found : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Found : user_pref("ConduitEngine.initDone", true);
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultthis.engineName", "XfireXO Customized Web Search");
Found : user_pref("browser.search.order.1", "Crawler Search");
Found : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;media_btn_wa;shout_btn_wa;ai[...]
Found : user_pref("winamp_toolbar.firsttime.showwindow", false);
Found : user_pref("winamp_toolbar.install.lastTbVersion", "5.5.1.1");
Found : user_pref("winamp_toolbar.metrics.activestampdate", "17");
Found : user_pref("winamp_toolbar.metrics.activestampmonth", "10");
Found : user_pref("winamp_toolbar.metrics.activestampyear", "2009");
Found : user_pref("winamp_toolbar.metrics.originalDate", "9");
Found : user_pref("winamp_toolbar.metrics.originalHours", "9");
Found : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Found : user_pref("winamp_toolbar.metrics.originalMonth", "1");
Found : user_pref("winamp_toolbar.metrics.originalSeconds", "21");
Found : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Found : user_pref("winamp_toolbar.search.populateoncomplete", false);
Found : user_pref("winamp_toolbar.search.searchtype", "web");
Found : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Found : user_pref("winamp_toolbar.upgrade.showwindow", false);
Found : user_pref("winamp_toolbar.winamp.artist", "");
Found : user_pref("winamp_toolbar.winamp.title", "-999999");
Found : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Found : user_pref("winamp_toolbar.winamp.tracktime", "-999998");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\johny\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [42371 octets] - [31/10/2012 13:43:13]
########## EOF - C:\AdwCleaner[R1].txt - [42432 octets] ##########
Re: Pravdepodobne infikovaný notebook. (RSIT log)

- Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
- Kliknete na Delete
- PC provede opravu, restartuje se a da Vam log (C:\AdwCleaner [S1].txt) , jeho obsah vlozte sem
Re: Pravdepodobne infikovaný notebook. (RSIT log)
# AdwCleaner v2.006 - Logfile created 10/31/2012 at 15:12:26
# Updated 30/10/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : johny - MOJPC
# Boot Mode : Normal
# Running from : C:\Users\johny\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Askcom.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Conduit.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-3.xml
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Softonic-Eng7
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Users\johny\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\johny\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\johny\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\johny\AppData\LocalLow\free-downloads.net
Folder Deleted : C:\Users\johny\AppData\LocalLow\Softonic-Eng7
Folder Deleted : C:\Users\johny\AppData\Roaming\iWin
Folder Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\Conduit
Folder Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\ConduitEngine
Folder Deleted : C:\Users\johny\AppData\Roaming\OpenCandy
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CToolbar_UNINSTALL
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-Eng7 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{588F6892-E562-42BB-AE46-1400E5EBE913}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B2D230B5-FDDB-4102-BE68-4DB7ABD30EBD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2304157
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2405280
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\conduitEngine
Key Deleted : HKLM\Software\free-downloads.net
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAA9C7B9-73E7-44E7-A0B2-7B7D7EFDC4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-Eng7 Toolbar
Key Deleted : HKLM\Software\Softonic-Eng7
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{ECDEE021-0D17-467F-A1FF-C7A115230949}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - SearchAssistant] = hxxp://www.crawler.com/search/ie.aspx?tb_id=60347 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - CustomizeSearch] = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60347 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.crawler.com/homepage.aspx?tbid=60347 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\prefs.js
Deleted : user_pref("CT2405280..clientLogIsEnabled", true);
Deleted : user_pref("CT2405280..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2405280..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2405280.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2405280.CTID", "CT2405280");
Deleted : user_pref("CT2405280.CurrentServerDate", "16-7-2011");
Deleted : user_pref("CT2405280.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2405280.DialogsGetterLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.DownloadReferralCookieData", "");
Deleted : user_pref("CT2405280.EMailNotifierPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedLastCount1783261708582779529", 702);
Deleted : user_pref("CT2405280.FeedPollDate129212394466815234", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815240", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815246", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815252", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815258", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815264", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815270", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815276", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815282", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815288", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815294", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815300", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815306", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815312", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971568", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971574", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971580", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971586", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971592", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971598", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971604", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971610", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971616", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971622", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971628", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971634", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971640", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971646", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971652", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971658", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971664", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971670", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971676", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971682", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971688", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971694", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971700", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971706", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127962", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127968", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127974", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127980", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127986", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127992", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127998", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128004", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128010", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128016", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128022", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128028", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128034", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128040", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedTTL129212394466815246", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466815258", 60);
Deleted : user_pref("CT2405280.FeedTTL129212394466815264", 10);
Deleted : user_pref("CT2405280.FeedTTL129212394466815312", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971568", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971574", 2);
Deleted : user_pref("CT2405280.FeedTTL129212394466971580", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971592", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971598", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971604", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971616", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971628", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971634", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971640", 2);
Deleted : user_pref("CT2405280.FeedTTL129212394466971658", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971670", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971676", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971682", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971700", 1440);
Deleted : user_pref("CT2405280.FeedTTL129212394467127980", 10);
Deleted : user_pref("CT2405280.FeedTTL129212394467127998", 5);
Deleted : user_pref("CT2405280.FirstServerDate", "14-7-2010");
Deleted : user_pref("CT2405280.FirstTime", true);
Deleted : user_pref("CT2405280.FirstTimeFF3", true);
Deleted : user_pref("CT2405280.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2405280.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2405280.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2405280.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2405280.Initialize", true);
Deleted : user_pref("CT2405280.InitializeCommonPrefs", true);
Deleted : user_pref("CT2405280.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT2405280.InstalledDate", "Wed Jul 14 2010 17:21:39 GMT+0200");
Deleted : user_pref("CT2405280.InvalidateCache", false);
Deleted : user_pref("CT2405280.IsGrouping", false);
Deleted : user_pref("CT2405280.IsOpenThankYouPage", false);
Deleted : user_pref("CT2405280.IsOpenUninstallPage", true);
Deleted : user_pref("CT2405280.LanguagePackLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2405280.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2405280.LastLogin_2.7.1.3", "Wed Jul 14 2010 17:21:40 GMT+0200");
Deleted : user_pref("CT2405280.LastLogin_3.3.3.2", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2405280.Locale", "en-us");
Deleted : user_pref("CT2405280.LoginCache", 4);
Deleted : user_pref("CT2405280.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2405280.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2405280.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2405280.RadioIsPodcast", false);
Deleted : user_pref("CT2405280.RadioLastCheckTime", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2405280.RadioLastUpdateServer", "129167775315800000");
Deleted : user_pref("CT2405280.RadioMediaID", "20503713");
Deleted : user_pref("CT2405280.RadioMediaType", "Media Player");
Deleted : user_pref("CT2405280.RadioMenuSelectedID", "EBRadioMenu_CT240528020503713");
Deleted : user_pref("CT2405280.RadioStationName", "Virgin%20Radio%20Classic%20Rock");
Deleted : user_pref("CT2405280.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[...]
Deleted : user_pref("CT2405280.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2405280.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2405280.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2405280.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[...]
Deleted : user_pref("CT2405280.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2405280.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2405280.SearchInNewTabLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2405280.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2405280.ServiceMapLastCheckTime", "Sat Jul 16 2011 21:34:25 GMT+0200");
Deleted : user_pref("CT2405280.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2405280.SettingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Deleted : user_pref("CT2405280.SettingsLastUpdate", "1309334663");
Deleted : user_pref("CT2405280.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastCheck", "Sat Jul 16 2011 21:34:25 GMT+0200");
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastUpdate", "1279117606");
Deleted : user_pref("CT2405280.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2405280");
Deleted : user_pref("CT2405280.UserID", "UN18001454394874772");
Deleted : user_pref("CT2405280.WeatherNetwork", "");
Deleted : user_pref("CT2405280.WeatherPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.WeatherUnit", "C");
Deleted : user_pref("CT2405280.alertChannelId", "799768");
Deleted : user_pref("CT2405280.clientLogIsEnabled", false);
Deleted : user_pref("CT2405280.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2405280.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2405280.globalFirstTimeInfoLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2405280.myStuffEnabled", true);
Deleted : user_pref("CT2405280.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2405280.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2405280.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2405280.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2405280.toolbarAppMetaDataLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.toolbarContextMenuLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2438727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2438727.CTID", "CT2438727");
Deleted : user_pref("CT2438727.CommunitiesChangesLastCheckTime", "0");
Deleted : user_pref("CT2438727.CurrentServerDate", "10-1-2011");
Deleted : user_pref("CT2438727.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2438727.DownloadReferralCookieData", "");
Deleted : user_pref("CT2438727.EMailNotifierPollDate", "Sun Oct 17 2010 18:01:56 GMT+0200");
Deleted : user_pref("CT2438727.FirstServerDate", "14-7-2010");
Deleted : user_pref("CT2438727.FirstTime", true);
Deleted : user_pref("CT2438727.FirstTimeFF3", true);
Deleted : user_pref("CT2438727.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2438727.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2438727.GroupingInvalidateCache", false);
Deleted : user_pref("CT2438727.GroupingLastCheckTime", "0");
Deleted : user_pref("CT2438727.GroupingLastServerUpdateTime", "0");
Deleted : user_pref("CT2438727.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2438727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2438727.Initialize", true);
Deleted : user_pref("CT2438727.InitializeCommonPrefs", true);
Deleted : user_pref("CT2438727.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2438727.InstalledDate", "Wed Jul 14 2010 16:23:14 GMT+0200");
Deleted : user_pref("CT2438727.InvalidateCache", false);
Deleted : user_pref("CT2438727.IsGrouping", false);
Deleted : user_pref("CT2438727.IsMulticommunity", false);
Deleted : user_pref("CT2438727.IsOpenThankYouPage", true);
Deleted : user_pref("CT2438727.IsOpenUninstallPage", true);
Deleted : user_pref("CT2438727.LanguagePackLastCheckTime", "Mon Jan 10 2011 14:07:45 GMT+0100");
Deleted : user_pref("CT2438727.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2438727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2438727.LastLogin_2.7.1.3", "Mon Jan 10 2011 18:08:15 GMT+0100");
Deleted : user_pref("CT2438727.LatestVersion", "2.7.1.3");
Deleted : user_pref("CT2438727.Locale", "en");
Deleted : user_pref("CT2438727.LoginCache", 4);
Deleted : user_pref("CT2438727.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2438727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2438727.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2438727.RadioIsPodcast", false);
Deleted : user_pref("CT2438727.RadioLastCheckTime", "Sun Oct 17 2010 12:59:33 GMT+0200");
Deleted : user_pref("CT2438727.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2438727.RadioLastUpdateServer", "0");
Deleted : user_pref("CT2438727.RadioMediaID", "9962");
Deleted : user_pref("CT2438727.RadioMediaType", "Media Player");
Deleted : user_pref("CT2438727.RadioMenuSelectedID", "EBRadioMenu_CT24387279962");
Deleted : user_pref("CT2438727.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2438727.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2438727.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2438727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2438727.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2438727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Deleted : user_pref("CT2438727.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2438727.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2438727.SearchInNewTabLastCheckTime", "Mon Jan 10 2011 14:07:44 GMT+0100");
Deleted : user_pref("CT2438727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2438727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2438727.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2438727.SettingsLastCheckTime", "Mon Jan 10 2011 16:32:28 GMT+0100");
Deleted : user_pref("CT2438727.SettingsLastUpdate", "1287517459");
Deleted : user_pref("CT2438727.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2438727.ThirdPartyComponentsLastCheck", "Sat Jan 08 2011 00:14:36 GMT+0100");
Deleted : user_pref("CT2438727.ThirdPartyComponentsLastUpdate", "1278548974");
Deleted : user_pref("CT2438727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2438727.UserID", "UN61348303777439454");
Deleted : user_pref("CT2438727.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2438727.WeatherNetwork", "");
Deleted : user_pref("CT2438727.WeatherPollDate", "Sun Oct 17 2010 18:01:57 GMT+0200");
Deleted : user_pref("CT2438727.WeatherUnit", "C");
Deleted : user_pref("CT2438727.alertChannelId", "832836");
Deleted : user_pref("CT2438727.clientLogIsEnabled", true);
Deleted : user_pref("CT2438727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2438727.myStuffEnabled", true);
Deleted : user_pref("CT2438727.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2438727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2438727.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2438727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2438727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2786678..clientLogIsEnabled", true);
Deleted : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2786678.CTID", "CT2786678");
Deleted : user_pref("CT2786678.CurrentServerDate", "29-4-2011");
Deleted : user_pref("CT2786678.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2786678.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:48 GMT+0200");
Deleted : user_pref("CT2786678.DownloadReferralCookieData", "");
Deleted : user_pref("CT2786678.EMailNotifierPollDate", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedLastCount5690698542593514850", 185);
Deleted : user_pref("CT2786678.FeedPollDate129301619375443753", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375443759", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444699", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444705", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444711", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444717", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444723", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444729", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444735", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444741", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444747", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedTTL129301619375444699", 10);
Deleted : user_pref("CT2786678.FeedTTL129301619375444723", 15);
Deleted : user_pref("CT2786678.FeedTTL129301619375444735", 5);
Deleted : user_pref("CT2786678.FeedTTL129301619375444747", 5);
Deleted : user_pref("CT2786678.FirstServerDate", "29-4-2011");
Deleted : user_pref("CT2786678.FirstTime", true);
Deleted : user_pref("CT2786678.FirstTimeFF3", true);
Deleted : user_pref("CT2786678.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2786678.HasUserGlobalKeys", true);
Deleted : user_pref("CT2786678.Initialize", true);
Deleted : user_pref("CT2786678.InitializeCommonPrefs", true);
Deleted : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1);
Deleted : user_pref("CT2786678.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2786678.InstalledDate", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("CT2786678.IsGrouping", false);
Deleted : user_pref("CT2786678.IsMulticommunity", false);
Deleted : user_pref("CT2786678.IsOpenThankYouPage", true);
Deleted : user_pref("CT2786678.IsOpenUninstallPage", false);
Deleted : user_pref("CT2786678.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:47 GMT+0200");
Deleted : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2786678.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:40 GMT+0200");
Deleted : user_pref("CT2786678.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2786678.Locale", "en");
Deleted : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Deleted : user_pref("CT2786678.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Fri Apr 29 2011 16:01:40 GMT+0200");
Deleted : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2786678.ServiceMapLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.SettingsLastUpdate", "1297856274");
Deleted : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246786978");
Deleted : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
Deleted : user_pref("CT2786678.UserID", "UN53507959899756299");
Deleted : user_pref("CT2786678.WeatherNetwork", "");
Deleted : user_pref("CT2786678.WeatherPollDate", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.WeatherUnit", "C");
Deleted : user_pref("CT2786678.alertChannelId", "1178763");
Deleted : user_pref("CT2786678.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Deleted : user_pref("CT2786678.myStuffEnabled", true);
Deleted : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2786678.testingCtid", "");
Deleted : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+0200");
Deleted : user_pref("CT2786678.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/SK", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2405280", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=2.5.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2786678",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63443493058760[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2405280/CT2405280[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalize[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.EngineHiddenByUser", false);
Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2786678");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar");
Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Feb 26 2012 11:49:11 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Feb 26 2012 11:49:03 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "6ee531ef-29d3-4d53-9122-9476f17ea0f2");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Deleted : user_pref("CommunityToolbar.globalUserId", "ce5141bd-5242-437a-bb41-b94434f4c833");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2304157");
Deleted : user_pref("CommunityToolbar.twitter.user_21817319.LastCheckTime", "Fri Feb 18 2011 17:16:30 GMT+0100[...]
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:02:12 GMT+0200");
Deleted : user_pref("ConduitEngine.FirstServerDate", "04/29/2011 17");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.FixPageNotFoundErrors", false);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstallationType", "UnknownIntegration");
Deleted : user_pref("ConduitEngine.InstalledDate", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", false);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:41 GMT+0200");
Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("ConduitEngine.UserID", "UN26450304765024135");
Deleted : user_pref("ConduitEngine.engineLocale", "cs");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultthis.engineName", "XfireXO Customized Web Search");
Deleted : user_pref("browser.search.order.1", "Crawler Search");
Deleted : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;media_btn_wa;shout_btn_wa;ai[...]
Deleted : user_pref("winamp_toolbar.firsttime.showwindow", false);
Deleted : user_pref("winamp_toolbar.install.lastTbVersion", "5.5.1.1");
Deleted : user_pref("winamp_toolbar.metrics.activestampdate", "17");
Deleted : user_pref("winamp_toolbar.metrics.activestampmonth", "10");
Deleted : user_pref("winamp_toolbar.metrics.activestampyear", "2009");
Deleted : user_pref("winamp_toolbar.metrics.originalDate", "9");
Deleted : user_pref("winamp_toolbar.metrics.originalHours", "9");
Deleted : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Deleted : user_pref("winamp_toolbar.metrics.originalMonth", "1");
Deleted : user_pref("winamp_toolbar.metrics.originalSeconds", "21");
Deleted : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Deleted : user_pref("winamp_toolbar.search.populateoncomplete", false);
Deleted : user_pref("winamp_toolbar.search.searchtype", "web");
Deleted : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Deleted : user_pref("winamp_toolbar.upgrade.showwindow", false);
Deleted : user_pref("winamp_toolbar.winamp.artist", "");
Deleted : user_pref("winamp_toolbar.winamp.title", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracktime", "-999998");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\johny\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [42502 octets] - [31/10/2012 13:43:13]
AdwCleaner[S1].txt - [42340 octets] - [31/10/2012 15:12:26]
########## EOF - C:\AdwCleaner[S1].txt - [42401 octets] ##########
# Updated 30/10/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : johny - MOJPC
# Boot Mode : Normal
# Running from : C:\Users\johny\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Askcom.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\Conduit.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-2.xml
File Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\searchplugins\icqplugin-3.xml
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Softonic-Eng7
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Users\johny\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\johny\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\johny\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\johny\AppData\LocalLow\free-downloads.net
Folder Deleted : C:\Users\johny\AppData\LocalLow\Softonic-Eng7
Folder Deleted : C:\Users\johny\AppData\Roaming\iWin
Folder Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\Conduit
Folder Deleted : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\ConduitEngine
Folder Deleted : C:\Users\johny\AppData\Roaming\OpenCandy
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CToolbar_UNINSTALL
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic-Eng7 Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Winamp Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{588F6892-E562-42BB-AE46-1400E5EBE913}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B2D230B5-FDDB-4102-BE68-4DB7ABD30EBD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2304157
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2405280
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\conduitEngine
Key Deleted : HKLM\Software\free-downloads.net
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAA9C7B9-73E7-44E7-A0B2-7B7D7EFDC4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6EF4FD5F-DFCF-4A1C-B3FA-D80A66F9F62D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Softonic-Eng7 Toolbar
Key Deleted : HKLM\Software\Softonic-Eng7
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{ECDEE021-0D17-467F-A1FF-C7A115230949}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - SearchAssistant] = hxxp://www.crawler.com/search/ie.aspx?tb_id=60347 --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - CustomizeSearch] = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60347 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.crawler.com/homepage.aspx?tbid=60347 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com
-\\ Mozilla Firefox v16.0.1 (cs)
Profile name : default
File : C:\Users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\prefs.js
Deleted : user_pref("CT2405280..clientLogIsEnabled", true);
Deleted : user_pref("CT2405280..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2405280..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2405280.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2405280.CTID", "CT2405280");
Deleted : user_pref("CT2405280.CurrentServerDate", "16-7-2011");
Deleted : user_pref("CT2405280.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2405280.DialogsGetterLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.DownloadReferralCookieData", "");
Deleted : user_pref("CT2405280.EMailNotifierPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedLastCount1783261708582779529", 702);
Deleted : user_pref("CT2405280.FeedPollDate129212394466815234", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815240", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815246", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815252", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815258", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815264", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815270", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815276", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815282", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815288", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815294", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815300", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815306", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466815312", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971568", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971574", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971580", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971586", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971592", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971598", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971604", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971610", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971616", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971622", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971628", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971634", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971640", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971646", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971652", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971658", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971664", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971670", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971676", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971682", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971688", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971694", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971700", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394466971706", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127962", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127968", "Sat Jul 16 2011 21:34:30 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127974", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127980", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127986", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127992", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467127998", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128004", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128010", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128016", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128022", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128028", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128034", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedPollDate129212394467128040", "Sat Jul 16 2011 21:34:31 GMT+0200");
Deleted : user_pref("CT2405280.FeedTTL129212394466815246", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466815258", 60);
Deleted : user_pref("CT2405280.FeedTTL129212394466815264", 10);
Deleted : user_pref("CT2405280.FeedTTL129212394466815312", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971568", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971574", 2);
Deleted : user_pref("CT2405280.FeedTTL129212394466971580", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971592", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971598", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971604", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971616", 5);
Deleted : user_pref("CT2405280.FeedTTL129212394466971628", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971634", 30);
Deleted : user_pref("CT2405280.FeedTTL129212394466971640", 2);
Deleted : user_pref("CT2405280.FeedTTL129212394466971658", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971670", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971676", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971682", 15);
Deleted : user_pref("CT2405280.FeedTTL129212394466971700", 1440);
Deleted : user_pref("CT2405280.FeedTTL129212394467127980", 10);
Deleted : user_pref("CT2405280.FeedTTL129212394467127998", 5);
Deleted : user_pref("CT2405280.FirstServerDate", "14-7-2010");
Deleted : user_pref("CT2405280.FirstTime", true);
Deleted : user_pref("CT2405280.FirstTimeFF3", true);
Deleted : user_pref("CT2405280.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2405280.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2405280.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2405280.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2405280.Initialize", true);
Deleted : user_pref("CT2405280.InitializeCommonPrefs", true);
Deleted : user_pref("CT2405280.InstallationAndCookieDataSentCount", 2);
Deleted : user_pref("CT2405280.InstalledDate", "Wed Jul 14 2010 17:21:39 GMT+0200");
Deleted : user_pref("CT2405280.InvalidateCache", false);
Deleted : user_pref("CT2405280.IsGrouping", false);
Deleted : user_pref("CT2405280.IsOpenThankYouPage", false);
Deleted : user_pref("CT2405280.IsOpenUninstallPage", true);
Deleted : user_pref("CT2405280.LanguagePackLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2405280.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2405280.LastLogin_2.7.1.3", "Wed Jul 14 2010 17:21:40 GMT+0200");
Deleted : user_pref("CT2405280.LastLogin_3.3.3.2", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2405280.Locale", "en-us");
Deleted : user_pref("CT2405280.LoginCache", 4);
Deleted : user_pref("CT2405280.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2405280.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2405280.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2405280.RadioIsPodcast", false);
Deleted : user_pref("CT2405280.RadioLastCheckTime", "Sat Jul 16 2011 21:34:27 GMT+0200");
Deleted : user_pref("CT2405280.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2405280.RadioLastUpdateServer", "129167775315800000");
Deleted : user_pref("CT2405280.RadioMediaID", "20503713");
Deleted : user_pref("CT2405280.RadioMediaType", "Media Player");
Deleted : user_pref("CT2405280.RadioMenuSelectedID", "EBRadioMenu_CT240528020503713");
Deleted : user_pref("CT2405280.RadioStationName", "Virgin%20Radio%20Classic%20Rock");
Deleted : user_pref("CT2405280.RadioStationURL", "hxxp://www.smgradio.com/core/audio/wmp/live.asx?service=vcbb[...]
Deleted : user_pref("CT2405280.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2405280.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2405280.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2405280.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT240[...]
Deleted : user_pref("CT2405280.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2405280.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2405280.SearchInNewTabLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2405280.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2405280.ServiceMapLastCheckTime", "Sat Jul 16 2011 21:34:25 GMT+0200");
Deleted : user_pref("CT2405280.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2405280.SettingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Deleted : user_pref("CT2405280.SettingsLastUpdate", "1309334663");
Deleted : user_pref("CT2405280.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastCheck", "Sat Jul 16 2011 21:34:25 GMT+0200");
Deleted : user_pref("CT2405280.ThirdPartyComponentsLastUpdate", "1279117606");
Deleted : user_pref("CT2405280.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2405280");
Deleted : user_pref("CT2405280.UserID", "UN18001454394874772");
Deleted : user_pref("CT2405280.WeatherNetwork", "");
Deleted : user_pref("CT2405280.WeatherPollDate", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.WeatherUnit", "C");
Deleted : user_pref("CT2405280.alertChannelId", "799768");
Deleted : user_pref("CT2405280.clientLogIsEnabled", false);
Deleted : user_pref("CT2405280.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2405280.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2405280.globalFirstTimeInfoLastCheckTime", "Sat Jul 16 2011 21:34:29 GMT+0200");
Deleted : user_pref("CT2405280.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2405280.myStuffEnabled", true);
Deleted : user_pref("CT2405280.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2405280.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2405280.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2405280.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2405280.toolbarAppMetaDataLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.toolbarContextMenuLastCheckTime", "Sat Jul 16 2011 21:34:28 GMT+0200");
Deleted : user_pref("CT2405280.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2438727.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2438727.CTID", "CT2438727");
Deleted : user_pref("CT2438727.CommunitiesChangesLastCheckTime", "0");
Deleted : user_pref("CT2438727.CurrentServerDate", "10-1-2011");
Deleted : user_pref("CT2438727.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2438727.DownloadReferralCookieData", "");
Deleted : user_pref("CT2438727.EMailNotifierPollDate", "Sun Oct 17 2010 18:01:56 GMT+0200");
Deleted : user_pref("CT2438727.FirstServerDate", "14-7-2010");
Deleted : user_pref("CT2438727.FirstTime", true);
Deleted : user_pref("CT2438727.FirstTimeFF3", true);
Deleted : user_pref("CT2438727.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2438727.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2438727.GroupingInvalidateCache", false);
Deleted : user_pref("CT2438727.GroupingLastCheckTime", "0");
Deleted : user_pref("CT2438727.GroupingLastServerUpdateTime", "0");
Deleted : user_pref("CT2438727.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2438727.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2438727.Initialize", true);
Deleted : user_pref("CT2438727.InitializeCommonPrefs", true);
Deleted : user_pref("CT2438727.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2438727.InstalledDate", "Wed Jul 14 2010 16:23:14 GMT+0200");
Deleted : user_pref("CT2438727.InvalidateCache", false);
Deleted : user_pref("CT2438727.IsGrouping", false);
Deleted : user_pref("CT2438727.IsMulticommunity", false);
Deleted : user_pref("CT2438727.IsOpenThankYouPage", true);
Deleted : user_pref("CT2438727.IsOpenUninstallPage", true);
Deleted : user_pref("CT2438727.LanguagePackLastCheckTime", "Mon Jan 10 2011 14:07:45 GMT+0100");
Deleted : user_pref("CT2438727.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2438727.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2438727.LastLogin_2.7.1.3", "Mon Jan 10 2011 18:08:15 GMT+0100");
Deleted : user_pref("CT2438727.LatestVersion", "2.7.1.3");
Deleted : user_pref("CT2438727.Locale", "en");
Deleted : user_pref("CT2438727.LoginCache", 4);
Deleted : user_pref("CT2438727.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2438727.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2438727.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2438727.RadioIsPodcast", false);
Deleted : user_pref("CT2438727.RadioLastCheckTime", "Sun Oct 17 2010 12:59:33 GMT+0200");
Deleted : user_pref("CT2438727.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2438727.RadioLastUpdateServer", "0");
Deleted : user_pref("CT2438727.RadioMediaID", "9962");
Deleted : user_pref("CT2438727.RadioMediaType", "Media Player");
Deleted : user_pref("CT2438727.RadioMenuSelectedID", "EBRadioMenu_CT24387279962");
Deleted : user_pref("CT2438727.RadioStationName", "California%20Rock");
Deleted : user_pref("CT2438727.RadioStationURL", "hxxp://feedlive.net/california.asx");
Deleted : user_pref("CT2438727.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2438727.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2438727.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2438727.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT243[...]
Deleted : user_pref("CT2438727.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2438727.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2438727.SearchInNewTabLastCheckTime", "Mon Jan 10 2011 14:07:44 GMT+0100");
Deleted : user_pref("CT2438727.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2438727.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2438727.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2438727.SettingsLastCheckTime", "Mon Jan 10 2011 16:32:28 GMT+0100");
Deleted : user_pref("CT2438727.SettingsLastUpdate", "1287517459");
Deleted : user_pref("CT2438727.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2438727.ThirdPartyComponentsLastCheck", "Sat Jan 08 2011 00:14:36 GMT+0100");
Deleted : user_pref("CT2438727.ThirdPartyComponentsLastUpdate", "1278548974");
Deleted : user_pref("CT2438727.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2438727.UserID", "UN61348303777439454");
Deleted : user_pref("CT2438727.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2438727.WeatherNetwork", "");
Deleted : user_pref("CT2438727.WeatherPollDate", "Sun Oct 17 2010 18:01:57 GMT+0200");
Deleted : user_pref("CT2438727.WeatherUnit", "C");
Deleted : user_pref("CT2438727.alertChannelId", "832836");
Deleted : user_pref("CT2438727.clientLogIsEnabled", true);
Deleted : user_pref("CT2438727.clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2438727.myStuffEnabled", true);
Deleted : user_pref("CT2438727.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2438727.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2438727.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2438727.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2438727.uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2786678..clientLogIsEnabled", true);
Deleted : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2786678.CTID", "CT2786678");
Deleted : user_pref("CT2786678.CurrentServerDate", "29-4-2011");
Deleted : user_pref("CT2786678.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2786678.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:48 GMT+0200");
Deleted : user_pref("CT2786678.DownloadReferralCookieData", "");
Deleted : user_pref("CT2786678.EMailNotifierPollDate", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedLastCount5690698542593514850", 185);
Deleted : user_pref("CT2786678.FeedPollDate129301619375443753", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375443759", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444699", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444705", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444711", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444717", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444723", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444729", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444735", "Fri Apr 29 2011 17:07:06 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444741", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedPollDate129301619375444747", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.FeedTTL129301619375444699", 10);
Deleted : user_pref("CT2786678.FeedTTL129301619375444723", 15);
Deleted : user_pref("CT2786678.FeedTTL129301619375444735", 5);
Deleted : user_pref("CT2786678.FeedTTL129301619375444747", 5);
Deleted : user_pref("CT2786678.FirstServerDate", "29-4-2011");
Deleted : user_pref("CT2786678.FirstTime", true);
Deleted : user_pref("CT2786678.FirstTimeFF3", true);
Deleted : user_pref("CT2786678.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2786678.HasUserGlobalKeys", true);
Deleted : user_pref("CT2786678.Initialize", true);
Deleted : user_pref("CT2786678.InitializeCommonPrefs", true);
Deleted : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1);
Deleted : user_pref("CT2786678.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2786678.InstalledDate", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("CT2786678.IsGrouping", false);
Deleted : user_pref("CT2786678.IsMulticommunity", false);
Deleted : user_pref("CT2786678.IsOpenThankYouPage", true);
Deleted : user_pref("CT2786678.IsOpenUninstallPage", false);
Deleted : user_pref("CT2786678.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:47 GMT+0200");
Deleted : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2786678.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:40 GMT+0200");
Deleted : user_pref("CT2786678.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2786678.Locale", "en");
Deleted : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Deleted : user_pref("CT2786678.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Fri Apr 29 2011 16:01:40 GMT+0200");
Deleted : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2786678.ServiceMapLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.SettingsLastUpdate", "1297856274");
Deleted : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246786978");
Deleted : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
Deleted : user_pref("CT2786678.UserID", "UN53507959899756299");
Deleted : user_pref("CT2786678.WeatherNetwork", "");
Deleted : user_pref("CT2786678.WeatherPollDate", "Fri Apr 29 2011 17:07:07 GMT+0200");
Deleted : user_pref("CT2786678.WeatherUnit", "C");
Deleted : user_pref("CT2786678.alertChannelId", "1178763");
Deleted : user_pref("CT2786678.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Deleted : user_pref("CT2786678.myStuffEnabled", true);
Deleted : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2786678.testingCtid", "");
Deleted : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+0200");
Deleted : user_pref("CT2786678.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1178763/1174448/SK", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2405280", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=2.5.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2786678",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63443493058760[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2405280/CT2405280[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2786678/CT2786678[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/equalize[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/minimize[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/play.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/stop.gif[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/StarFleet/vol.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.EngineHiddenByUser", false);
Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2786678");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "utorrentbar");
Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2786678");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "utorrentbar");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "chrome://browser-region/locale/region.pr[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2438727,CT2405280,ConduitEngine,CT2786678");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Fri Apr 29 2011 16:01:43 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun Feb 26 2012 11:49:11 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Sun Feb 26 2012 11:49:03 GMT+0100");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "6ee531ef-29d3-4d53-9122-9476f17ea0f2");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sat Jul 16 2011 21:34:26 GMT+0200");
Deleted : user_pref("CommunityToolbar.globalUserId", "ce5141bd-5242-437a-bb41-b94434f4c833");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2304157");
Deleted : user_pref("CommunityToolbar.twitter.user_21817319.LastCheckTime", "Fri Feb 18 2011 17:16:30 GMT+0100[...]
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Fri Apr 29 2011 16:02:12 GMT+0200");
Deleted : user_pref("ConduitEngine.FirstServerDate", "04/29/2011 17");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.FixPageNotFoundErrors", false);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.HideEngineAfterRestart", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstallationType", "UnknownIntegration");
Deleted : user_pref("ConduitEngine.InstalledDate", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", false);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Fri Apr 29 2011 16:01:41 GMT+0200");
Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Fri Apr 29 2011 16:01:37 GMT+0200");
Deleted : user_pref("ConduitEngine.UserID", "UN26450304765024135");
Deleted : user_pref("ConduitEngine.engineLocale", "cs");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Fri Apr 29 2011 16:01:38 GMT+0200");
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Fri Apr 29 2011 16:05:42 GMT+0200");
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultthis.engineName", "XfireXO Customized Web Search");
Deleted : user_pref("browser.search.order.1", "Crawler Search");
Deleted : user_pref("winamp_toolbar.buttons.layout", "skins_btn_wa;plugins_btn_wa;media_btn_wa;shout_btn_wa;ai[...]
Deleted : user_pref("winamp_toolbar.firsttime.showwindow", false);
Deleted : user_pref("winamp_toolbar.install.lastTbVersion", "5.5.1.1");
Deleted : user_pref("winamp_toolbar.metrics.activestampdate", "17");
Deleted : user_pref("winamp_toolbar.metrics.activestampmonth", "10");
Deleted : user_pref("winamp_toolbar.metrics.activestampyear", "2009");
Deleted : user_pref("winamp_toolbar.metrics.originalDate", "9");
Deleted : user_pref("winamp_toolbar.metrics.originalHours", "9");
Deleted : user_pref("winamp_toolbar.metrics.originalMinutes", "1");
Deleted : user_pref("winamp_toolbar.metrics.originalMonth", "1");
Deleted : user_pref("winamp_toolbar.metrics.originalSeconds", "21");
Deleted : user_pref("winamp_toolbar.metrics.originalYear", "2009");
Deleted : user_pref("winamp_toolbar.search.populateoncomplete", false);
Deleted : user_pref("winamp_toolbar.search.searchtype", "web");
Deleted : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Deleted : user_pref("winamp_toolbar.upgrade.showwindow", false);
Deleted : user_pref("winamp_toolbar.winamp.artist", "");
Deleted : user_pref("winamp_toolbar.winamp.title", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracktime", "-999998");
-\\ Google Chrome v [Unable to get version]
File : C:\Users\johny\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [42502 octets] - [31/10/2012 13:43:13]
AdwCleaner[S1].txt - [42340 octets] - [31/10/2012 15:12:26]
########## EOF - C:\AdwCleaner[S1].txt - [42401 octets] ##########
Re: Pravdepodobne infikovaný notebook. (RSIT log)

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"=- [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"=- [-HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3}"=- [-HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Startup Cleaner"=- "LogMeIn Hamachi Ui"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui] File:: c:\program files\Softonic-Eng7\tbSoft.dll C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\ParetoLogic Registration3.job C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job C:\Windows\tasks\ParetoLogic Update Version3.job C:\Windows\tasks\RegCure Pro.job DDS:: uStart Page = hxxp://www.crawler.com/homepage.aspx?tbid=60347 uInternet Settings,ProxyOverride = <local> uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: &U????????? - c:\program files\NamiRobot\Data\du.html Firefox:: FF - ProfilePath - c:\users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\ FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?cl ... s:official Driver:: KFJZNW VECJ gupdate gupdatem ClearJavaCache:: Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte


Re: Pravdepodobne infikovaný notebook. (RSIT log)
Ospravedlňujem sa že tak pozde, ale bol som mimo domova.
ComboFix 12-10-30.03 - johny . 11. 2012 10:23:05.10.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3066.1894 [GMT 1:00]
Running from: c:\users\johny\Desktop\ComboFix.exe
Command switches used :: c:\users\johny\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\Softonic-Eng7\tbSoft.dll"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\ParetoLogic Registration3.job"
"c:\windows\tasks\ParetoLogic Update Version3 Startup Task.job"
"c:\windows\tasks\ParetoLogic Update Version3.job"
"c:\windows\tasks\RegCure Pro.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_KFJZNW
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_KFJZNW
-------\Service_VECJ
.
.
((((((((((((((((((((((((( Files Created from 2012-10-10 to 2012-11-10 )))))))))))))))))))))))))))))))
.
.
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:36 -------- d-----w- c:\users\johny\AppData\Local\temp
2012-11-01 16:25 . 2012-11-01 20:09 -------- d-----w- c:\programdata\Tunngle
2012-11-01 16:25 . 2012-11-01 16:28 -------- d-----w- c:\program files\Tunngle
2012-11-01 15:51 . 2012-11-10 09:04 -------- d-----w- c:\users\johny\AppData\Local\LogMeIn Hamachi
2012-11-01 15:50 . 2012-11-01 15:50 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-10-30 17:20 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-30 17:20 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-30 17:20 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-30 17:20 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-10-30 17:20 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-30 17:20 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-10-30 17:19 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-30 17:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-30 17:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-23 11:18 . 2012-05-06 12:40 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-23 11:18 . 2012-05-06 12:40 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-23 11:18 . 2012-05-06 12:40 360392 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-23 11:18 . 2012-05-06 12:40 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-23 11:18 . 2012-05-06 12:40 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-23 11:18 . 2012-05-06 12:40 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-23 11:17 . 2012-05-06 12:39 41224 ----a-w- c:\windows\avastSS.scr
2012-10-23 11:17 . 2012-05-06 12:39 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-17 01:32 . 2012-11-09 14:27 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0EB4A081-30FD-452D-8856-91DB9C02B09F}\mpengine.dll
2012-10-09 17:43 . 2012-05-19 07:56 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 17:43 . 2011-05-24 05:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-31 20:41 . 2012-10-31 20:41 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 11:17 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-23 397312]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-02 821768]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3607040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-05-12 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-05-12 167936]
"mouseElf"="c:\progra~1\TWINTO~1\MouseElf.EXE" [2004-08-26 192512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 18:04 2972160 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-06 20:42 34040 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
2008-03-07 01:36 544768 ----a-w- c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 17:43]
.
2012-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-11-09 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:07]
.
2012-11-10 c:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-25 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-26 c:\windows\Tasks\RegCure Pro.job
- c:\program files\ParetoLogic\RegCure Pro\RegCurePro.exe [2012-10-22 20:06]
.
.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &U????????? - c:\program files\NamiRobot\Data\du.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\
FF - ExtSQL: !HIDDEN! 2009-12-04 21:26; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-10 10:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\johny\AppData\Local\Temp\DRYD6E2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(5656)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\programdata\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe
c:\program files\LogMeIn Hamachi\hamachi-2.exe
c:\program files\Acer\Acer Bio Protection\BASVC.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\acer\Mobility Center\MobilityService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-11-10 10:41:56 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-10 09:41
ComboFix2.txt 2012-10-31 07:39
ComboFix3.txt 2012-02-26 19:06
ComboFix4.txt 2012-02-26 17:30
ComboFix5.txt 2012-11-10 09:20
.
Pre-Run: 75 387 510 784 bytes free
Post-Run: 73 653 399 552 bytes free
.
- - End Of File - - 998B5AAC720CDAE682F46121B78EE404
ComboFix 12-10-30.03 - johny . 11. 2012 10:23:05.10.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3066.1894 [GMT 1:00]
Running from: c:\users\johny\Desktop\ComboFix.exe
Command switches used :: c:\users\johny\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\Softonic-Eng7\tbSoft.dll"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\ParetoLogic Registration3.job"
"c:\windows\tasks\ParetoLogic Update Version3 Startup Task.job"
"c:\windows\tasks\ParetoLogic Update Version3.job"
"c:\windows\tasks\RegCure Pro.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_KFJZNW
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_KFJZNW
-------\Service_VECJ
.
.
((((((((((((((((((((((((( Files Created from 2012-10-10 to 2012-11-10 )))))))))))))))))))))))))))))))
.
.
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\Public\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-10 09:32 . 2012-11-10 09:36 -------- d-----w- c:\users\johny\AppData\Local\temp
2012-11-01 16:25 . 2012-11-01 20:09 -------- d-----w- c:\programdata\Tunngle
2012-11-01 16:25 . 2012-11-01 16:28 -------- d-----w- c:\program files\Tunngle
2012-11-01 15:51 . 2012-11-10 09:04 -------- d-----w- c:\users\johny\AppData\Local\LogMeIn Hamachi
2012-11-01 15:50 . 2012-11-01 15:50 -------- d-----w- c:\program files\LogMeIn Hamachi
2012-10-30 17:20 . 2012-06-02 00:02 985088 ----a-w- c:\windows\system32\crypt32.dll
2012-10-30 17:20 . 2012-06-02 00:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-30 17:20 . 2012-06-02 00:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-30 17:20 . 2012-05-11 15:57 623616 ----a-w- c:\windows\system32\localspl.dll
2012-10-30 17:20 . 2012-08-24 15:53 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-10-30 17:20 . 2012-07-04 14:02 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-10-30 17:19 . 2012-09-13 13:28 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-30 17:18 . 2012-08-29 11:27 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-30 17:18 . 2012-08-29 11:27 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-23 11:18 . 2012-05-06 12:40 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-23 11:18 . 2012-05-06 12:40 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-23 11:18 . 2012-05-06 12:40 360392 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-23 11:18 . 2012-05-06 12:40 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-23 11:18 . 2012-05-06 12:40 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-23 11:18 . 2012-05-06 12:40 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-23 11:17 . 2012-05-06 12:39 41224 ----a-w- c:\windows\avastSS.scr
2012-10-23 11:17 . 2012-05-06 12:39 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-17 01:32 . 2012-11-09 14:27 6918632 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0EB4A081-30FD-452D-8856-91DB9C02B09F}\mpengine.dll
2012-10-09 17:43 . 2012-05-19 07:56 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 17:43 . 2011-05-24 05:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-31 20:41 . 2012-10-31 20:41 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-23 11:17 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-04-23 397312]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-07-02 821768]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2009-01-09 3607040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-05-12 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-05-12 167936]
"mouseElf"="c:\progra~1\TWINTO~1\MouseElf.EXE" [2004-08-26 192512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-23 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-09 18:04 2972160 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-06 20:42 34040 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
2008-03-07 01:36 544768 ----a-w- c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-19 17:43]
.
2012-11-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 13:47]
.
2012-11-09 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:07]
.
2012-11-10 c:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-25 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:07]
.
2012-09-26 c:\windows\Tasks\RegCure Pro.job
- c:\program files\ParetoLogic\RegCure Pro\RegCurePro.exe [2012-10-22 20:06]
.
.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &U????????? - c:\program files\NamiRobot\Data\du.html
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\johny\AppData\Roaming\Mozilla\Firefox\Profiles\uumgwdji.default\
FF - ExtSQL: !HIDDEN! 2009-12-04 21:26; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-10 10:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\users\johny\AppData\Local\Temp\DRYD6E2.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(5656)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\programdata\{AAD0A813-CC18-4D28-A1CC-4DC0DF41A592}\Server.exe
c:\program files\LogMeIn Hamachi\hamachi-2.exe
c:\program files\Acer\Acer Bio Protection\BASVC.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\acer\Mobility Center\MobilityService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2012-11-10 10:41:56 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-10 09:41
ComboFix2.txt 2012-10-31 07:39
ComboFix3.txt 2012-02-26 19:06
ComboFix4.txt 2012-02-26 17:30
ComboFix5.txt 2012-11-10 09:20
.
Pre-Run: 75 387 510 784 bytes free
Post-Run: 73 653 399 552 bytes free
.
- - End Of File - - 998B5AAC720CDAE682F46121B78EE404