Díky za pomoc

Logfile of random's system information tool 1.09 (written by random/random)
Run by pavel at 2013-12-04 19:40:45
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 19 GB (13%) free of 140 GB
Total RAM: 1983 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:40:49, on 4.12.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ExpressFiles\EFupdater.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Gameforge4D\4Story\PrePatch.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Documents and Settings\pavel\Data aplikací\Yontoo\YontooDesktop.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe
C:\Documents and Settings\pavel\Data aplikací\Seznam.cz\bin\szndesktop.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\IObit\Advanced SystemCare 5\DelayLoad.exe
C:\Documents and Settings\pavel\Plocha\RSIT.exe
C:\Program Files\trend micro\pavel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1379094025
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=16194
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: BetterSurf - {6E3C6B04-08FE-43BC-8E50-F90285024DEA} - C:\Program Files\BetterSurf\ie\BetterSurf.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: BetterSrf - {8271B5D6-76D3-4ABF-AEB3-1721161C76BC} - C:\Program Files\Better-Surf\ie\BetterSrf.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: preispilotBHO - {E48592BA-1EE6-41EE-AEC7-3E6CB38E6FD8} - C:\Program Files\preispilot\Internet Explorer\preispilot.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: (no name) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - (no file)
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story\PrePatch.exe
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [gcleyyvfbo] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\gcleyyvfbo.vbs"
O4 - HKLM\..\Run: [iyuwhtdhhh] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\iyuwhtdhhh.vbs"
O4 - HKLM\..\Run: [smhxkjjues] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\smhxkjjues.vbs"
O4 - HKLM\..\Run: [sqgzfeckgg] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\sqgzfeckgg.vbs"
O4 - HKLM\..\Run: [unzzlqqpjt] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\unzzlqqpjt.vbs"
O4 - HKLM\..\Run: [dukbzmiypo] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\dukbzmiypo.vbs"
O4 - HKLM\..\Run: [rbxypdiyhk] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\rbxypdiyhk.vbs"
O4 - HKLM\..\Run: [hoqatdvbcp] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\hoqatdvbcp.vbs"
O4 - HKLM\..\Run: [tluigqomji] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\tluigqomji.vbs"
O4 - HKLM\..\Run: [brgponjtkm] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\brgponjtkm.vbs"
O4 - HKLM\..\Run: [iuxywlqrgl] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\iuxywlqrgl.vbs"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [frhvixpxsk] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\frhvixpxsk.vbs"
O4 - HKLM\..\Run: [08f4dc96bbb7af09d1a37fe35c75a42f] "C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe" ..
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Documents and Settings\pavel\Data aplikací\Yontoo\YontooDesktop.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Documents and Settings\pavel\Data aplikací\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Documents and Settings\pavel\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\pavel\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [gcleyyvfbo] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\gcleyyvfbo.vbs"
O4 - HKCU\..\Run: [iyuwhtdhhh] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\iyuwhtdhhh.vbs"
O4 - HKCU\..\Run: [dukbzmiypo] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\dukbzmiypo.vbs"
O4 - HKCU\..\Run: [hoqatdvbcp] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\hoqatdvbcp.vbs"
O4 - HKCU\..\Run: [sqgzfeckgg] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\sqgzfeckgg.vbs"
O4 - HKCU\..\Run: [rbxypdiyhk] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\rbxypdiyhk.vbs"
O4 - HKCU\..\Run: [smhxkjjues] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\smhxkjjues.vbs"
O4 - HKCU\..\Run: [unzzlqqpjt] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\unzzlqqpjt.vbs"
O4 - HKCU\..\Run: [brgponjtkm] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\brgponjtkm.vbs"
O4 - HKCU\..\Run: [tluigqomji] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\tluigqomji.vbs"
O4 - HKCU\..\Run: [iuxywlqrgl] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\iuxywlqrgl.vbs"
O4 - HKCU\..\Run: [08f4dc96bbb7af09d1a37fe35c75a42f] "C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe" ..
O4 - HKCU\..\Run: [frhvixpxsk] wscript.exe //B "C:\DOCUME~1\pavel\LOCALS~1\Temp\frhvixpxsk.vbs"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe -update activex
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: 08f4dc96bbb7af09d1a37fe35c75a42f.exe
O4 - Startup: brgponjtkm.vbs
O4 - Startup: dukbzmiypo.vbs
O4 - Startup: frhvixpxsk.vbs
O4 - Startup: gcleyyvfbo.vbs
O4 - Startup: hoqatdvbcp.vbs
O4 - Startup: iuxywlqrgl.vbs
O4 - Startup: iyuwhtdhhh.vbs
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: rbxypdiyhk.vbs
O4 - Startup: smhxkjjues.vbs
O4 - Startup: sqgzfeckgg.vbs
O4 - Startup: tluigqomji.vbs
O4 - Startup: unzzlqqpjt.vbs
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.cz/Genoogle/Compo ... eQuery.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 7221306703
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O17 - HKLM\System\CS2\Services\Tcpip\..\{145E60DA-D108-4BBE-B20F-CBD7FEABD268}: NameServer = 192.168.119.1,212.80.66.7
O17 - HKLM\System\CS3\Services\Tcpip\..\{145E60DA-D108-4BBE-B20F-CBD7FEABD268}: NameServer = 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c987b8732a557a) (gupdate1c987b8732a557a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
--
End of file - 15185 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AmiUpdXp.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Express Files Updater.job
C:\WINDOWS\tasks\Express FilesUpdate.job
C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1275210071-1659004503-682003330-1005Core.job
C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1275210071-1659004503-682003330-1005UA.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RMAutoUpdate.job
C:\WINDOWS\tasks\RMSchedule.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\SmartDefrag_Startup.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{0CA60AAA-8D2C-48AB-98AF-129F1E8D71E7}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{972F2DEE-DDD3-450D-8B28-B0CC55A5BBC7}.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\pavel\Data aplikací\Mozilla\Firefox\Profiles\i0tlqmcm.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.qvo6.com/?utm_source=b&utm_m ... 1379094025"
prefs.js - "extensions.enabledItems" - "{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}:4.1.4.0, jqs@sun.com:1.0, {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}:1.5.0.850, {20a82645-c095-46ed-80e3-08825760534b}:1.1, {2224E955-00E9-4613-A844-CE69FCCAAE91}:3.4.0.4340, {EEE6C361-6118-11DC-9C72-001320C79847}:1.0.0.10, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {DDABDBA1-2377-4A30-A027-25697B99E254}:3.1, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.yahoo.com/search?fr=green ... =685749&p="
"{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}"=C:\Program Files\DoubleD\GamingHarbor Toolbar\4.1.4.20920\FFToolbar
"{2224E955-00E9-4613-A844-CE69FCCAAE91}"=C:\Program Files\Internet Saving Optimizer\3.4.0.4340\FF
"{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}"=C:\Program Files\Media Access Startup\1.5.0.850\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"xz123@ya456.com"=C:\Program Files\BetterSurf\ff
"12x3q@3244516.com"=C:\Program Files\Better-Surf\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1204144.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@ngm.nexoneu.com/NxGame]
"Description"=Nexon Game Controller
"Path"=C:\Documents and Settings\All Users\Data aplikací\NexonEU\NGM\npNxGameeu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll
C:\Documents and Settings\pavel\Data aplikací\Mozilla\Firefox\Profiles\i0tlqmcm.default\extensions\
ffxtlbr@babylon.com
{800b5000-a755-47e1-992b-48a1c1357f07}
{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Documents and Settings\pavel\Data aplikací\Mozilla\Firefox\Profiles\i0tlqmcm.default\searchplugins\
askcomsearch.xml
babylon.xml
conduit.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin.xml
sweetim.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}]
BetterSurf - C:\Program Files\BetterSurf\ie\BetterSurf.dll [2013-11-12 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-10-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC}]
Better-Surf - C:\Program Files\Better-Surf\ie\BetterSrf.dll [2013-11-25 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-05-14 4531320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2013-01-24 1521800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E48592BA-1EE6-41EE-AEC7-3E6CB38E6FD8}]
Preispilot - C:\Program Files\preispilot\Internet Explorer\preispilot.dll [2012-04-04 182016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]
{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2013-01-24 1521800]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2012-02-21 327680]
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe [2013-01-24 1646216]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"gcleyyvfbo"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\gcleyyvfbo.vbs []
"iyuwhtdhhh"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\iyuwhtdhhh.vbs []
"smhxkjjues"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\smhxkjjues.vbs []
"sqgzfeckgg"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\sqgzfeckgg.vbs []
"unzzlqqpjt"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\unzzlqqpjt.vbs []
"dukbzmiypo"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\dukbzmiypo.vbs []
"rbxypdiyhk"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\rbxypdiyhk.vbs []
"hoqatdvbcp"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\hoqatdvbcp.vbs []
"tluigqomji"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\tluigqomji.vbs []
"brgponjtkm"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\brgponjtkm.vbs []
"iuxywlqrgl"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\iuxywlqrgl.vbs []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"frhvixpxsk"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\frhvixpxsk.vbs []
"08f4dc96bbb7af09d1a37fe35c75a42f"=C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe [2013-10-12 156672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ7.6\ICQ.exe [2011-10-10 127040]
"Advanced SystemCare 5"=C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe [2011-12-29 620376]
"Yontoo Desktop"=C:\Documents and Settings\pavel\Data aplikací\Yontoo\YontooDesktop.exe [2013-01-31 42784]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2013-05-20 4284976]
"cz.seznam.software.autoupdate"=C:\Documents and Settings\pavel\Data aplikací\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Documents and Settings\pavel\Data aplikací\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"Facebook Update"=C:\Documents and Settings\pavel\Local Settings\Data aplikací\Facebook\Update\FacebookUpdate.exe [2013-10-21 138096]
"gcleyyvfbo"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\gcleyyvfbo.vbs []
"iyuwhtdhhh"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\iyuwhtdhhh.vbs []
"dukbzmiypo"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\dukbzmiypo.vbs []
"hoqatdvbcp"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\hoqatdvbcp.vbs []
"sqgzfeckgg"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\sqgzfeckgg.vbs []
"rbxypdiyhk"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\rbxypdiyhk.vbs []
"smhxkjjues"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\smhxkjjues.vbs []
"unzzlqqpjt"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\unzzlqqpjt.vbs []
"brgponjtkm"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\brgponjtkm.vbs []
"tluigqomji"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\tluigqomji.vbs []
"iuxywlqrgl"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\iuxywlqrgl.vbs []
"08f4dc96bbb7af09d1a37fe35c75a42f"=C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe [2013-10-12 156672]
"frhvixpxsk"=wscript.exe //B C:\DOCUME~1\pavel\LOCALS~1\Temp\frhvixpxsk.vbs []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe [2013-10-08 829832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4StoryPrePatch]
C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2012-02-21 327680]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2011-03-04 2741616]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2006-10-31 7634944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2006-10-31 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-07-05 16380416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe [2013-11-27 1383232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2013-10-21 20549280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2007-06-15 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2005-10-26 159744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-22 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\SweetIM\Messenger\SweetIM.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-10-04 393216]
C:\Documents and Settings\pavel\Nabídka Start\Programy\Po spuštění
08f4dc96bbb7af09d1a37fe35c75a42f.exe
brgponjtkm.vbs
dukbzmiypo.vbs
frhvixpxsk.vbs
gcleyyvfbo.vbs
hoqatdvbcp.vbs
iuxywlqrgl.vbs
iyuwhtdhhh.vbs
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
rbxypdiyhk.vbs
smhxkjjues.vbs
sqgzfeckgg.vbs
tluigqomji.vbs
unzzlqqpjt.vbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Documents and Settings\Owner\Plocha\Agora_downloader_98828d.exe"="C:\Documents and Settings\Owner\Plocha\Agora_downloader_98828d.exe:*:Enabled:ExpressFilesInstaller"
"C:\Documents and Settings\All Users\Data aplikací\NexonEU\NGM\NGM.exe"="C:\Documents and Settings\All Users\Data aplikací\NexonEU\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1040\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1737\Agent.exe"="C:\Documents and Settings\All Users\Data aplikací\Battle.net\Agent\Agent.1737\Agent.exe:*:Enabled:Battle.net Update Agent"
"C:\Program Files\ExpressFiles\ExpressDL.exe"="C:\Program Files\ExpressFiles\ExpressDL.exe:*:Enabled:Express Files"
"C:\Documents and Settings\pavel\Plocha\Age Of Empires 2 CZ!!!!\empires2.exe"="C:\Documents and Settings\pavel\Plocha\Age Of Empires 2 CZ!!!!\empires2.exe:*:Enabled:Age of Empires II"
"C:\Documents and Settings\pavel\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe"="C:\Documents and Settings\pavel\Local Settings\Data aplikací\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Owner\Local Settings\Temp\explorer.exe"="C:\Documents and Settings\Owner\Local Settings\Temp\explorer.exe:*:Enabled:explorer.exe"
"C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe"="C:\Documents and Settings\pavel\Local Settings\Temp\explorer.exe:*:Enabled:explorer.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ.exe"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.lhacm"=lhacm.acm
"vidc.DIVX"=DivX.dll
======List of files/folders created in the last 1 month======
2013-12-04 19:37:35 ----D---- C:\rsit
2013-12-04 19:37:35 ----D---- C:\Program Files\trend micro
2013-12-04 19:22:57 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2013-12-02 17:06:16 ----D---- C:\Program Files\Common Files\Java
2013-12-02 17:06:08 ----A---- C:\WINDOWS\system32\javaws.exe
2013-12-02 17:05:59 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-12-02 17:05:59 ----A---- C:\WINDOWS\system32\javaw.exe
2013-12-02 17:05:59 ----A---- C:\WINDOWS\system32\java.exe
2013-11-27 18:35:31 ----D---- C:\Program Files\IObit Toolbar
2013-11-27 18:35:31 ----D---- C:\Program Files\Common Files\Spigot
2013-11-27 18:35:31 ----D---- C:\Program Files\Application Updater
2013-11-25 21:38:09 ----D---- C:\Program Files\Better-Surf
2013-11-18 22:43:31 ----D---- C:\Program Files\Mozilla Firefox
2013-11-18 18:03:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2013-11-18 18:02:17 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2013-11-18 18:01:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2013-11-18 18:01:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2013-11-13 21:38:14 ----D---- C:\Program Files\BetterSurf
======List of files/folders modified in the last 1 month======
2013-12-04 19:38:55 ----SHD---- C:\WINDOWS\Installer
2013-12-04 19:38:54 ----D---- C:\Config.Msi
2013-12-04 19:38:16 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-12-04 19:38:13 ----D---- C:\WINDOWS\Prefetch
2013-12-04 19:37:35 ----D---- C:\Program Files
2013-12-04 19:36:16 ----D---- C:\WINDOWS\Temp
2013-12-04 19:35:47 ----D---- C:\Documents and Settings\pavel\Data aplikací\Seznam.cz
2013-12-04 19:33:54 ----D---- C:\Program Files\CCleaner
2013-12-04 19:31:17 ----D---- C:\Documents and Settings\pavel\Data aplikací\Yontoo
2013-12-04 19:29:24 ----D---- C:\Program Files\PC Tools Registry Mechanic
2013-12-04 19:29:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-12-04 19:27:52 ----D---- C:\WINDOWS\system32\CatRoot2
2013-12-04 19:22:59 ----D---- C:\WINDOWS
2013-12-04 19:22:57 ----D---- C:\WINDOWS\system32\drivers
2013-12-04 19:14:17 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2013-12-04 19:12:06 ----D---- C:\WINDOWS\system32
2013-12-04 19:09:26 ----D---- C:\WINDOWS\Debug
2013-12-02 17:07:54 ----D---- C:\WINDOWS\system32\config
2013-12-02 17:06:16 ----D---- C:\Program Files\Common Files
2013-12-02 17:05:59 ----D---- C:\Program Files\Java
2013-12-02 17:04:58 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-11-26 21:21:47 ----D---- C:\Documents and Settings\pavel\Data aplikací\Skype
2013-11-20 20:12:17 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-11-18 18:16:37 ----HD---- C:\WINDOWS\inf
2013-11-18 18:03:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-11-18 18:02:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-11-17 10:36:30 ----D---- C:\WINDOWS\system32\CatRoot
2013-11-17 10:36:21 ----D---- C:\WINDOWS\ie8updates
2013-11-17 10:32:15 ----D---- C:\Program Files\Internet Explorer
2013-11-17 10:30:43 ----D---- C:\WINDOWS\system32\MRT
2013-11-17 10:27:24 ----A---- C:\WINDOWS\system32\MRT.exe
2013-11-10 11:10:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2013-11-10 11:10:05 ----RD---- C:\Program Files\Skype
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-10-18 105472]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-11-28 30808]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43008]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-11-28 34392]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-11-28 435032]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-11-28 314456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-11-28 52952]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2013-06-25 242240]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-11-28 20568]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-11-28 111320]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-18 4547584]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-11-27 58368]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-11-27 19968]
S0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\catchme.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-08-26 17480]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
S3 K320bus;Sony Ericsson K320 driver (WDM); C:\WINDOWS\system32\DRIVERS\K320bus.sys [2006-08-18 61504]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\K320mdfl.sys [2006-08-18 9328]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\K320mdm.sys [2006-08-18 97056]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\K320mgmt.sys [2006-08-18 88560]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\K320obex.sys [2006-08-18 86368]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5; C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-29 497496]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2013-11-27 807800]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-10-08 182696]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2011-03-04 73728]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-08-21 794272]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-11-22 3290304]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate1c987b8732a557a;Google Update Service (gupdate1c987b8732a557a); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-31 155715]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10 257416]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-05 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-11-18 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------