Logfile of random's system information tool 1.10 (written by random/random)
Run by sosna at 2016-04-29 17:04:56
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 44 GB (30%) free of 148 GB
Total RAM: 3000 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:05:01, on 29.4.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16773)
Boot mode: Normal
Running processes:
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Ruzne programy\Winamp\winampa.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Ruzne programy\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\sosna\AppData\Local\Temp\RtkBtMnt.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gAutoPan.exe
C:\Genius\ioCentre\gAutoScroll.exe
C:\Genius\ioCentre\gZoom.exe
C:\Genius\ioCentre\gMGlass.exe
C:\Genius\ioCentre\gIMMgm.exe
C:\Genius\ioCentre\gDeskMgm.exe
C:\Genius\ioCentre\gTaskSwitch.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Ruzne programy\BSplayer\bsplayer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ESET\ESET Smart Security\eOPPFrame.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\Downloads\RSIT.exe
C:\Program Files\trend micro\sosna.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx ... =11&lng=cs
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_custom ... tbid=80093
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Ruzne programy\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Ruzne programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\ccleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 13587 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineUA1d0403c48accce0.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\User_Feed_Synchronization-{91A658F1-6916-485F-A9A7-2BA80CAC3873}.job - C:\Windows\system32\msfeedssync.exe sync
=========Mozilla firefox=========
ProfilePath - C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "gemgecko@gemius.com:1.02, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.2.5.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "http://toolbar.inbox.com/search/dispatc ... ge=en&qkw="
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=C:\Program Files\Crawler\Toolbar\firefox\
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.73.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.73.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(11)
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\searchplugins\
inbox-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
Yahoo! Toolbar Helper
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2015-09-24 68504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-20 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14 142896]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"BkupTray"=C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-04-10 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-04-10 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-04-18 167936]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-13 6183456]
"Skytel"=C:\Windows\Skytel.exe [2007-11-21 1826816]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-09-11 809480]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-05-14 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-06-11 409600]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"WinampAgent"=C:\Ruzne programy\Winamp\winampa.exe [2008-08-04 36352]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2007-04-13 61440]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2015-03-02 2477056]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2014-01-17 1284680]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2014-01-15 438888]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-01-29 594992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Ruzne programy\DAEMON Tools\daemon.exe [2007-08-29 171464]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-02 21644384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\ccleaner.exe [2016-04-15 6675672]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"cz.seznam.software.autoupdate"=C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"uTorrent"=C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe [2016-04-07 1959424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.tscc"=tsccvid.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-04-29 16:56:04 ----D---- C:\Program Files\trend micro
2016-04-29 16:56:03 ----D---- C:\rsit
2016-04-28 05:07:59 ----D---- C:\Program Files\Mozilla Firefox
2016-04-17 03:48:28 ----A---- C:\Windows\system32\msxml3.dll
2016-04-17 03:45:50 ----A---- C:\Windows\system32\ncrypt.dll
2016-04-17 03:45:43 ----A---- C:\Windows\system32\secur32.dll
2016-04-17 03:45:41 ----A---- C:\Windows\system32\samlib.dll
2016-04-17 03:45:39 ----A---- C:\Windows\system32\samsrv.dll
2016-04-17 03:45:36 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-17 03:43:23 ----A---- C:\Windows\system32\tzres.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\ole32.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\kernel32.dll
2016-04-17 03:18:16 ----A---- C:\Windows\system32\ntdll.dll
2016-04-17 03:09:40 ----A---- C:\Windows\system32\msorcl32.dll
2016-04-17 03:09:39 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-17 03:08:33 ----A---- C:\Windows\system32\win32k.sys
2016-04-16 13:32:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\urlmon.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\mshta.exe
2016-04-16 13:32:36 ----A---- C:\Windows\system32\msfeedssync.exe
2016-04-16 13:32:35 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-16 13:32:35 ----A---- C:\Windows\system32\jsproxy.dll
2016-04-16 13:32:34 ----A---- C:\Windows\system32\ieUnatt.exe
2016-04-16 13:32:33 ----A---- C:\Windows\system32\iertutil.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\url.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\dxtmsft.dll
2016-04-16 13:32:30 ----A---- C:\Windows\system32\ieframe.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\wininet.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\vbscript.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\ieui.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-16 13:32:22 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-16 13:32:21 ----A---- C:\Windows\system32\jscript.dll
2016-04-16 13:32:17 ----A---- C:\Windows\system32\mshtml.dll
2016-04-16 13:32:14 ----A---- C:\Windows\system32\jscript9.dll
2016-04-07 17:18:37 ----D---- C:\Users\sosna\AppData\Roaming\uTorrent
======List of files/folders modified in the last 1 month======
2016-04-29 17:05:01 ----D---- C:\Windows\temp
2016-04-29 16:56:04 ----RD---- C:\Program Files
2016-04-29 12:39:23 ----D---- C:\Windows\System32
2016-04-29 12:39:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 12:39:22 ----D---- C:\Windows\inf
2016-04-28 07:33:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-27 07:08:30 ----D---- C:\Program Files\CCleaner
2016-04-27 04:12:53 ----SHD---- C:\System Volume Information
2016-04-22 18:39:34 ----D---- C:\ProgramData\CanonIJPLM
2016-04-21 15:05:04 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 08:45:23 ----D---- C:\Windows\Debug
2016-04-21 08:45:23 ----D---- C:\Windows
2016-04-17 17:59:51 ----D---- C:\Program Files\ZbrojniPrukaz
2016-04-17 05:25:37 ----D---- C:\Users\sosna\AppData\Roaming\Skype
2016-04-17 04:31:14 ----D---- C:\Windows\rescache
2016-04-17 04:21:36 ----D---- C:\Users\sosna\AppData\Roaming\Seznam.cz
2016-04-17 04:06:26 ----D---- C:\Windows\system32\sk-SK
2016-04-17 04:06:26 ----D---- C:\Windows\system32\migration
2016-04-17 04:06:25 ----D---- C:\Program Files\Internet Explorer
2016-04-17 03:50:40 ----SHD---- C:\Windows\Installer
2016-04-17 03:50:31 ----D---- C:\ProgramData\Microsoft Help
2016-04-17 03:48:56 ----D---- C:\Windows\winsxs
2016-04-17 03:48:53 ----D---- C:\Windows\system32\catroot
2016-04-17 03:46:53 ----D---- C:\Windows\system32\catroot2
2016-04-17 03:39:34 ----D---- C:\Windows\system32\MRT
2016-04-17 03:36:38 ----D---- C:\Windows\Microsoft.NET
2016-04-17 03:29:20 ----RSD---- C:\Windows\assembly
2016-04-17 03:22:05 ----A---- C:\Windows\system32\mrt.exe
2016-04-17 03:08:12 ----D---- C:\Windows\system32\XPSViewer
2016-04-08 19:16:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 18:21:12 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-03-17 71488]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-05-14 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-04 685816]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-03-17 206312]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-20 146024]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-03-17 152728]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-03-17 44608]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-10-28 5632]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2015-11-20 111040]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-03-21 15392]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-05-14 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-05-14 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-29 952832]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2007-04-13 16384]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2007-03-13 9856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-06-14 2152344]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-31 14848]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2012-03-29 47360]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-08-12 61440]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-25 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 aeoscmso;aeoscmso; C:\Windows\system32\drivers\aeoscmso.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 catchme;catchme; \??\C:\Users\sosna\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 ICDUSB2;Sony IC Recorder (P); C:\Windows\System32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-21 654336]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-05-14 500784]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-03-17 1983264]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxcr_device;lxcr_device; C:\Windows\system32\lxcrcoms.exe [2006-12-11 537520]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 eins2038;Eset install launcher (20382); C:\Windows\eins2038.dll,RDServiceStart eins2038 C:\Users\sosna\AppData\Local\Temp\inxE834.tmp []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08 269504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-28 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu, dochází k zasekávání počítače
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 60
- Registrován: 01 srp 2006 11:54
- Rudy
- Site Admin
- Příspěvky: 119492
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu, dochází k zasekávání počítače
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 60
- Registrován: 01 srp 2006 11:54
Re: Prosím o kontrolu, dochází k zasekávání počítače
# AdwCleaner v5.114 - Logfile created 29/04/2016 at 18:06:43
# Updated 27/04/2016 by Xplode
# Database : 2016-04-27.1 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (X86)
# Username : sosna - SOSNA-PC
# Running from : C:\Users\sosna\Downloads\adwcleaner_5.114.exe
# Option : Clean
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Genius
[-] Folder Deleted : C:\Users\sosna\AppData\Local\VirtualStore\Program Files\Convesoft
[-] Folder Deleted : C:\Users\sosna\AppData\LocalLow\AppGraffiti
[-] Folder Deleted : C:\Users\sosna\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
***** [ Files ] *****
[-] File Deleted : C:\Program Files\Yahoo!\Common\unyt.exe
***** [ DLLs ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crawler lišta\Nápověda pro lištu.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crawler lišta\Více produktů Crawler.lnk
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
[-] Key Deleted : HKCU\Software\Classes\Applications\updater.exe
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
[-] Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Toolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKCU\Software\AppDataLow\Software\MyAshampoo\toolbar
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\MyAshampoo\toolbar
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1109296668-1472727054-2438046157-1000\Software\Yahoo\Companion
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [SearchAssistant]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [CustomizeSearch]
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Value Deleted : HKU\S-1-5-21-1109296668-1472727054-2438046157-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
***** [ Web browsers ] *****
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..clientLogIsEnabled", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481020.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481024.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481025.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481029.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481031.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481032.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481033.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481034.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481035.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481037.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CTID", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesChangesLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2475029", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2481033", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2481037", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CurrentServerDate", "4-5-2012");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DialogsAlignMode", "LTR");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsCheckInterval", "168");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsListLastCheckTime", "Wed May 02 2012 06:46:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsListLastServerUpdateTime", "1201069983");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadReferralCookieData", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.EMailNotifierPollDate", "Tue Mar 27 2012 15:20:34 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedLastCount129133095456874337", 277);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029379", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029381", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029382", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129133095459686870", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129133095459686871", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687146", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687147", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687148", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029379", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029381", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029382", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129133095459686870", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129133095459686871", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687146", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687147", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687148", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstServerDate", "26-3-2012");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstTime", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstTimeFF3", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FixPageNotFoundErrors", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingInvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastErrorCode", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastResponse", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastServerUpdateTime", "129804383910000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingServerCheckInterval", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.HasUserGlobalKeys", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.Initialize", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InitializeCommonPrefs", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationAndCookieDataSentCount", 3);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationId", "MyAshampoo.exe");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationType", "ConduitIntegration");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstalledDate", "Mon Mar 26 2012 21:14:59 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsGrouping", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsMulticommunity", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsOpenThankYouPage", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsOpenUninstallPage", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackReloadIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LastLogin_3.2.5.2", "Fri May 04 2012 09:10:38 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LatestVersion", "3.12.2.3");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.Locale", "en");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipHeight", "83");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipWidth", "295");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioIsPodcast", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioLastCheckTime", "Tue Mar 27 2012 15:27:39 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioLastUpdateIPServer", "0");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMediaID", "9962");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMediaType", "Media Player");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMenuSelectedID", "EBRadioMenu_CT24750299962");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioShrinked", "shrinked");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioStationName", "California%20Rock");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioStationURL", "hxxp://feedlive.net/california.asx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SHRINK_TOOLBAR", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SavedHomepage", "www.seznam.cz");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchBoxWidth", 243);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchFromAddressBarIsInit", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabEnabled", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ServiceMapLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SettingsLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SettingsLastUpdate", "1335953991");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsInterval", 504);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsLastCheck", "Tue Apr 17 2012 07:31:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsLastUpdate", "1312887586");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.UserID", "UN59103298126899246");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ValidationData_Toolbar", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherNetwork", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherPollDate", "Tue Mar 27 2012 16:06:42 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherUnit", "C");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cb_firstuse0100", "31");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cb_user_id_000", "43423534313732343536353736395F46697265666F78");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cbcountry_000", "435A");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cbfirsttime", "5361742041707220303720323031322032313A33333A333920474D542B30323030");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.shoppingapp.gk.exipres", "576564204D617920303920323031322030393A31303A333920474D542B30323030");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.shoppingapp.gk.geolocation", "637A6563682072657075626C6963");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.url_history0001", "687474703A2F2F7365617263682E73657A6E616D2E637A2F3F713D25433525393965636B6F2B6B72254333254139746126636F756E743D3130267049643D496E64516379575F43447[...]
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000034", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000080", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000082", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000234", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129054281793738287", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129125397313902904", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129133095456874337", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129342246831062526", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129374111428406428", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129464711670143239", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129469742085082050", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129582128742751739", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129584873345514033", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.DialogsAlignMode", "LTR");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingInvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastCheckTime", "Tue Mar 27 2012 15:22:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastErrorCode", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastResponse", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastServerUpdateTime", "129732820530000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.InvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.LanguagePackLastCheckTime", "Mon Mar 26 2012 21:15:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.Locale", "pl-pl");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.RadioLastCheckTime", "Tue Mar 27 2012 15:22:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.RadioLastUpdateIPServer", "0");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SearchInNewTabLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SettingsLastCheckTime", "Tue Mar 27 2012 15:22:50 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SettingsLastUpdate", "1329208420");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.ThirdPartyComponentsLastCheck", "Mon Mar 26 2012 21:14:59 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.ThirdPartyComponentsLastUpdate", "1254383982");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858466844285", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858468406855", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858469500631", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129391154315937643", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129469752568363385", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129469753375550431", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129529552075474834", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.toolbarAppMetaDataLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.toolbarContextMenuLastCheckTime", "Mon Mar 26 2012 21:15:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffEnabled", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffPublihserMinWidth", 400);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffServiceIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.testingCtid", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.toolbarAppMetaDataLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.toolbarContextMenuLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.usagesFlag", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2475029/CT2475029", "\"054070ecc802ba05b04be6349057c30f1\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2481033/CT2475029", "\"db073822ebdf27332368ff7a3d35a7691\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874426/870225/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874430/870228/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874431/870229/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874435/870233/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874437/870235/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874438/870236/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874439/870237/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874440/870238/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874441/870239/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874443/870241/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2475029", "\"1333628348\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2481033", "\"1308481897\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "m4Df43NZ+9lr21ZNdyYrjA==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=pl-pl", "VLSKF58Y6tTNJCe510DKJQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "B8Px/Te74hi98N2hb9yOAQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=pl-pl", "U0qwKRjRDEKX6cmSMItfMQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=pl-pl", "4OMPBR3L0MjxA6jJKZedsQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "cTVrc75U9YwdI74PAhUYFw==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=pl-pl", "Kp7DudRjOs1J7VmrJ1QR7g==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"d76323372b05c3748a3d6b1c93a98292\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equalizer_dead.gif", "\"0678fe477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/maxi.gif", "\"0639a4d477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimize.gif", "\"046c7ab477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gif", "\"0484de117c4c91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play_mini.gif", "\"0484de117c4c91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gif", "\"0e7a152347ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif", "\"087c778347ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"67e1ac93c8bab6bfc9801049c6b49194\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pl-pl", "\"2be62e9ee78b65a0cd1379134913adad\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/1344951.xml", "\"51882856885b153d457064ee9b4d9477\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/16887175.xml", "\"a7dddab62dbf76b5e0f90a195415d296\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/17151925.xml", "\"52cd94a30c2338a0836530940218f642\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20536157.xml", "\"618ed7d7a8561cfc219347d3e4cdce6c\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/30261067.xml", "\"accc5805c30a902f92f720a06d5fc990\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/34655603.xml", "\"73fc51864a10ca14c4bb75a3e42b1568\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/759251.xml", "\"1c6248e5a1c102017a8825ae460ed353\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/816653.xml", "\"abef5188a22d030a61834798bce31539\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "myashampoo");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "myashampoo");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tmpl=11&tbid=80093&language=en&qkw=");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.locale", "en");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.userId", "3dec8853-f4bc-40bf-b2d6-3b1204c1b5b3");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_16887175.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_17151925.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_20536157.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_30261067.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_34655603.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_759251.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstServerDate", "03/26/2012 22");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstTime", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.Initialize", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.UserID", "UN25203947372691426");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.engineLocale", "en-US");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.initDone", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.order.1", "Crawler Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.selectedEngine", "MyAshampoo Customized Web Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("keyword.URL", "hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tmpl=11&tbid=80093&language=en&qkw=");
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [50146 bytes] - [29/04/2016 18:06:43]
C:\AdwCleaner\AdwCleaner[S1].txt - [49504 bytes] - [29/04/2016 18:02:35]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [50294 bytes] ##########
# Updated 27/04/2016 by Xplode
# Database : 2016-04-27.1 [Server]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (X86)
# Username : sosna - SOSNA-PC
# Running from : C:\Users\sosna\Downloads\adwcleaner_5.114.exe
# Option : Clean
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Genius
[-] Folder Deleted : C:\Users\sosna\AppData\Local\VirtualStore\Program Files\Convesoft
[-] Folder Deleted : C:\Users\sosna\AppData\LocalLow\AppGraffiti
[-] Folder Deleted : C:\Users\sosna\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
***** [ Files ] *****
[-] File Deleted : C:\Program Files\Yahoo!\Common\unyt.exe
***** [ DLLs ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crawler lišta\Nápověda pro lištu.lnk
[-] Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crawler lišta\Více produktů Crawler.lnk
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search
[-] Key Deleted : HKCU\Software\Classes\Applications\updater.exe
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
[-] Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Toolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKCU\Software\AppDataLow\Software\MyAshampoo\toolbar
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\MyAshampoo\toolbar
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1109296668-1472727054-2438046157-1000\Software\Yahoo\Companion
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [SearchAssistant]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [CustomizeSearch]
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
[#] Value Deleted : HKU\S-1-5-21-1109296668-1472727054-2438046157-1000\Software\Microsoft\Internet Explorer\SearchScopes [DoNotAskAgain]
***** [ Web browsers ] *****
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..clientLogIsEnabled", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481020.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481024.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481025.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481029.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481031.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481032.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481033.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481034.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481035.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CT2481037.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CTID", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesChangesLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2475029", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2481033", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunitiesStatus.CT2481037", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CommunityChanged", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.CurrentServerDate", "4-5-2012");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DialogsAlignMode", "LTR");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsCheckInterval", "168");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsListLastCheckTime", "Wed May 02 2012 06:46:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadDomainsListLastServerUpdateTime", "1201069983");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.DownloadReferralCookieData", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.EMailNotifierPollDate", "Tue Mar 27 2012 15:20:34 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedLastCount129133095456874337", 277);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029379", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029381", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129132307482029382", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129133095459686870", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129133095459686871", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687146", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687147", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedPollDate129137437659687148", "Tue Mar 27 2012 15:25:45 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029379", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029381", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129132307482029382", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129133095459686870", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129133095459686871", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687146", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687147", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FeedTTL129137437659687148", 40);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstServerDate", "26-3-2012");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstTime", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FirstTimeFF3", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.FixPageNotFoundErrors", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingInvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastErrorCode", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastResponse", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingLastServerUpdateTime", "129804383910000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingServerCheckInterval", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.HasUserGlobalKeys", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.Initialize", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InitializeCommonPrefs", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationAndCookieDataSentCount", 3);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationId", "MyAshampoo.exe");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstallationType", "ConduitIntegration");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InstalledDate", "Mon Mar 26 2012 21:14:59 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.InvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsGrouping", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsMulticommunity", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsOpenThankYouPage", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.IsOpenUninstallPage", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackReloadIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LastLogin_3.2.5.2", "Fri May 04 2012 09:10:38 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.LatestVersion", "3.12.2.3");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.Locale", "en");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipHeight", "83");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.MCDetectTooltipWidth", "295");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioIsPodcast", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioLastCheckTime", "Tue Mar 27 2012 15:27:39 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioLastUpdateIPServer", "0");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMediaID", "9962");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMediaType", "Media Player");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioMenuSelectedID", "EBRadioMenu_CT24750299962");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioShrinked", "shrinked");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioStationName", "California%20Rock");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.RadioStationURL", "hxxp://feedlive.net/california.asx");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SHRINK_TOOLBAR", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SavedHomepage", "www.seznam.cz");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchBoxWidth", 243);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchFromAddressBarIsInit", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabEnabled", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ServiceMapLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SettingsLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.SettingsLastUpdate", "1335953991");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsInterval", 504);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsLastCheck", "Tue Apr 17 2012 07:31:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ThirdPartyComponentsLastUpdate", "1312887586");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/EB_ORIGINAL_CTID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.UserID", "UN59103298126899246");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ValidationData_Toolbar", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherNetwork", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherPollDate", "Tue Mar 27 2012 16:06:42 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.WeatherUnit", "C");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cb_firstuse0100", "31");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cb_user_id_000", "43423534313732343536353736395F46697265666F78");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cbcountry_000", "435A");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.cbfirsttime", "5361742041707220303720323031322032313A33333A333920474D542B30323030");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.shoppingapp.gk.exipres", "576564204D617920303920323031322030393A31303A333920474D542B30323030");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.shoppingapp.gk.geolocation", "637A6563682072657075626C6963");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.backendstorage.url_history0001", "687474703A2F2F7365617263682E73657A6E616D2E637A2F3F713D25433525393965636B6F2B6B72254333254139746126636F756E743D3130267049643D496E64516379575F43447[...]
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000034", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000080", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000082", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.1000234", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129054281793738287", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129125397313902904", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129133095456874337", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129342246831062526", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129374111428406428", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129464711670143239", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129469742085082050", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129582128742751739", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.components.129584873345514033", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.DialogsAlignMode", "LTR");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingInvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastCheckTime", "Tue Mar 27 2012 15:22:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastErrorCode", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastResponse", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.GroupingLastServerUpdateTime", "129732820530000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.InvalidateCache", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.LanguagePackLastCheckTime", "Mon Mar 26 2012 21:15:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.Locale", "pl-pl");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.RadioLastCheckTime", "Tue Mar 27 2012 15:22:52 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.RadioLastUpdateIPServer", "0");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SearchInNewTabLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SettingsLastCheckTime", "Tue Mar 27 2012 15:22:50 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.SettingsLastUpdate", "1329208420");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.ThirdPartyComponentsLastCheck", "Mon Mar 26 2012 21:14:59 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.ThirdPartyComponentsLastUpdate", "1254383982");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858466844285", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858468406855", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129058858469500631", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129391154315937643", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129469752568363385", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129469753375550431", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.components.129529552075474834", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.toolbarAppMetaDataLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.ct2481033.toolbarContextMenuLastCheckTime", "Mon Mar 26 2012 21:15:02 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffEnabled", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffPublihserMinWidth", 400);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffServiceIntervalMM", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.testingCtid", "");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.toolbarAppMetaDataLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.toolbarContextMenuLastCheckTime", "Mon Mar 26 2012 21:15:01 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CT2475029.usagesFlag", 2);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2475029/CT2475029", "\"054070ecc802ba05b04be6349057c30f1\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2481033/CT2475029", "\"db073822ebdf27332368ff7a3d35a7691\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874426/870225/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874430/870228/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874431/870229/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874435/870233/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874437/870235/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874438/870236/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874439/870237/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874440/870238/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874441/870239/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/874443/870241/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/CZ", "\"0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2475029", "\"1333628348\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2481033", "\"1308481897\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "m4Df43NZ+9lr21ZNdyYrjA==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=pl-pl", "VLSKF58Y6tTNJCe510DKJQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "B8Px/Te74hi98N2hb9yOAQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=pl-pl", "U0qwKRjRDEKX6cmSMItfMQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=pl-pl", "4OMPBR3L0MjxA6jJKZedsQ==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "cTVrc75U9YwdI74PAhUYFw==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=pl-pl", "Kp7DudRjOs1J7VmrJ1QR7g==");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"d76323372b05c3748a3d6b1c93a98292\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "634356118310000000");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equalizer_dead.gif", "\"0678fe477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/maxi.gif", "\"0639a4d477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimize.gif", "\"046c7ab477ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gif", "\"0484de117c4c91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play_mini.gif", "\"0484de117c4c91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gif", "\"0e7a152347ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif", "\"087c778347ac91:0\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"67e1ac93c8bab6bfc9801049c6b49194\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pl-pl", "\"2be62e9ee78b65a0cd1379134913adad\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/1344951.xml", "\"51882856885b153d457064ee9b4d9477\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/16887175.xml", "\"a7dddab62dbf76b5e0f90a195415d296\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/17151925.xml", "\"52cd94a30c2338a0836530940218f642\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20536157.xml", "\"618ed7d7a8561cfc219347d3e4cdce6c\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/30261067.xml", "\"accc5805c30a902f92f720a06d5fc990\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/34655603.xml", "\"73fc51864a10ca14c4bb75a3e42b1568\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/759251.xml", "\"1c6248e5a1c102017a8825ae460ed353\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/816653.xml", "\"abef5188a22d030a61834798bce31539\"");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwner", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "myashampoo");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "myashampoo");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tmpl=11&tbid=80093&language=en&qkw=");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ToolbarsList", "ConduitEngine,CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.locale", "en");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Fri May 04 2012 09:10:37 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.alert.userId", "3dec8853-f4bc-40bf-b2d6-3b1204c1b5b3");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_16887175.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_17151925.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_20536157.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_30261067.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_34655603.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_759251.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Tue Mar 27 2012 15:25:47 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstServerDate", "03/26/2012 22");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstTime", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.Initialize", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.InstalledDate", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.LastLogin_3.2.5.2", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.PublisherContainerWidth", 0);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.UserID", "UN25203947372691426");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.engineLocale", "en-US");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Mar 26 2012 21:14:57 GMT+0200");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("ConduitEngine.initDone", true);
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.order.1", "Crawler Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("browser.search.selectedEngine", "MyAshampoo Customized Web Search");
[-] [C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\prefs.js] Deleted : user_pref("keyword.URL", "hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tmpl=11&tbid=80093&language=en&qkw=");
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C1].txt - [50146 bytes] - [29/04/2016 18:06:43]
C:\AdwCleaner\AdwCleaner[S1].txt - [49504 bytes] - [29/04/2016 18:02:35]
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [50294 bytes] ##########
- Rudy
- Site Admin
- Příspěvky: 119492
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu, dochází k zasekávání počítače
Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 60
- Registrován: 01 srp 2006 11:54
Re: Prosím o kontrolu, dochází k zasekávání počítače
Logfile of random's system information tool 1.10 (written by random/random)
Run by sosna at 2016-04-29 19:36:24
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 44 GB (30%) free of 148 GB
Total RAM: 3000 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:36:36, on 29.4.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16773)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Ruzne programy\Winamp\winampa.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxext.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Ruzne programy\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Canon\My Image Garden\cnmigmain.exe
C:\Windows\explorer.exe
C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\sosna\AppData\Roaming\uTorrent\updates\3.4.6_42094\utorrentie.exe
C:\Users\sosna\AppData\Roaming\uTorrent\updates\3.4.6_42094\utorrentie.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\Downloads\RSIT.exe
C:\Program Files\trend micro\sosna.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Ruzne programy\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Ruzne programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 12967 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineUA1d0403c48accce0.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\User_Feed_Synchronization-{91A658F1-6916-485F-A9A7-2BA80CAC3873}.job - C:\Windows\system32\msfeedssync.exe sync
=========Mozilla firefox=========
ProfilePath - C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "gemgecko@gemius.com:1.02, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.2.5.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.73.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.73.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(11)
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\searchplugins\
inbox-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2015-09-24 68504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-20 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14 142896]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"BkupTray"=C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-04-10 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-04-10 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-04-18 167936]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-13 6183456]
"Skytel"=C:\Windows\Skytel.exe [2007-11-21 1826816]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-09-11 809480]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-05-14 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-06-11 409600]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"WinampAgent"=C:\Ruzne programy\Winamp\winampa.exe [2008-08-04 36352]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2015-03-02 2477056]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2014-01-17 1284680]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2014-01-15 438888]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-01-29 594992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Ruzne programy\DAEMON Tools\daemon.exe [2007-08-29 171464]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-02 21644384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-04-15 6675672]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"cz.seznam.software.autoupdate"=C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"uTorrent"=C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe [2016-04-07 1959424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.tscc"=tsccvid.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-04-29 18:02:11 ----D---- C:\AdwCleaner
2016-04-29 16:56:04 ----D---- C:\Program Files\trend micro
2016-04-29 16:56:03 ----D---- C:\rsit
2016-04-28 05:07:59 ----D---- C:\Program Files\Mozilla Firefox
2016-04-17 03:48:28 ----A---- C:\Windows\system32\msxml3.dll
2016-04-17 03:45:50 ----A---- C:\Windows\system32\ncrypt.dll
2016-04-17 03:45:43 ----A---- C:\Windows\system32\secur32.dll
2016-04-17 03:45:41 ----A---- C:\Windows\system32\samlib.dll
2016-04-17 03:45:39 ----A---- C:\Windows\system32\samsrv.dll
2016-04-17 03:45:36 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-17 03:43:23 ----A---- C:\Windows\system32\tzres.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\ole32.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\kernel32.dll
2016-04-17 03:18:16 ----A---- C:\Windows\system32\ntdll.dll
2016-04-17 03:09:40 ----A---- C:\Windows\system32\msorcl32.dll
2016-04-17 03:09:39 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-17 03:08:33 ----A---- C:\Windows\system32\win32k.sys
2016-04-16 13:32:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\urlmon.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\mshta.exe
2016-04-16 13:32:36 ----A---- C:\Windows\system32\msfeedssync.exe
2016-04-16 13:32:35 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-16 13:32:35 ----A---- C:\Windows\system32\jsproxy.dll
2016-04-16 13:32:34 ----A---- C:\Windows\system32\ieUnatt.exe
2016-04-16 13:32:33 ----A---- C:\Windows\system32\iertutil.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\url.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\dxtmsft.dll
2016-04-16 13:32:30 ----A---- C:\Windows\system32\ieframe.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\wininet.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\vbscript.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\ieui.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-16 13:32:22 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-16 13:32:21 ----A---- C:\Windows\system32\jscript.dll
2016-04-16 13:32:17 ----A---- C:\Windows\system32\mshtml.dll
2016-04-16 13:32:14 ----A---- C:\Windows\system32\jscript9.dll
2016-04-07 17:18:37 ----D---- C:\Users\sosna\AppData\Roaming\uTorrent
======List of files/folders modified in the last 1 month======
2016-04-29 19:36:22 ----D---- C:\Windows\temp
2016-04-29 18:30:15 ----D---- C:\Users\sosna\AppData\Roaming\Seznam.cz
2016-04-29 18:29:36 ----D---- C:\Windows\System32
2016-04-29 18:29:36 ----D---- C:\Windows\inf
2016-04-29 18:29:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 18:26:19 ----D---- C:\Users\sosna\AppData\Roaming\Skype
2016-04-29 18:13:46 ----D---- C:\Windows
2016-04-29 16:56:04 ----RD---- C:\Program Files
2016-04-28 07:33:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-27 07:08:30 ----D---- C:\Program Files\CCleaner
2016-04-27 04:12:53 ----SHD---- C:\System Volume Information
2016-04-22 18:39:34 ----D---- C:\ProgramData\CanonIJPLM
2016-04-21 15:05:04 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 08:45:23 ----D---- C:\Windows\Debug
2016-04-17 17:59:51 ----D---- C:\Program Files\ZbrojniPrukaz
2016-04-17 04:31:14 ----D---- C:\Windows\rescache
2016-04-17 04:06:26 ----D---- C:\Windows\system32\sk-SK
2016-04-17 04:06:26 ----D---- C:\Windows\system32\migration
2016-04-17 04:06:25 ----D---- C:\Program Files\Internet Explorer
2016-04-17 03:50:40 ----SHD---- C:\Windows\Installer
2016-04-17 03:50:31 ----D---- C:\ProgramData\Microsoft Help
2016-04-17 03:48:56 ----D---- C:\Windows\winsxs
2016-04-17 03:48:53 ----D---- C:\Windows\system32\catroot
2016-04-17 03:46:53 ----D---- C:\Windows\system32\catroot2
2016-04-17 03:39:34 ----D---- C:\Windows\system32\MRT
2016-04-17 03:36:38 ----D---- C:\Windows\Microsoft.NET
2016-04-17 03:29:20 ----RSD---- C:\Windows\assembly
2016-04-17 03:22:05 ----A---- C:\Windows\system32\mrt.exe
2016-04-17 03:08:12 ----D---- C:\Windows\system32\XPSViewer
2016-04-08 19:16:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 18:21:12 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-03-17 71488]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-05-14 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-04 685816]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-03-17 206312]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-20 146024]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-03-17 152728]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-03-17 44608]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-10-28 5632]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2015-11-20 111040]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-03-21 15392]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-05-14 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-05-14 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-29 952832]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2007-04-13 16384]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2007-03-13 9856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-06-14 2152344]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-31 14848]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2012-03-29 47360]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-08-12 61440]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-25 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 abn2srox;abn2srox; C:\Windows\system32\drivers\abn2srox.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 catchme;catchme; \??\C:\Users\sosna\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 ICDUSB2;Sony IC Recorder (P); C:\Windows\System32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-21 654336]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-05-14 500784]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-03-17 1983264]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxcr_device;lxcr_device; C:\Windows\system32\lxcrcoms.exe [2006-12-11 537520]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 eins2038;Eset install launcher (20382); C:\Windows\eins2038.dll,RDServiceStart eins2038 C:\Users\sosna\AppData\Local\Temp\inxE834.tmp []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08 269504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-28 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
Run by sosna at 2016-04-29 19:36:24
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 44 GB (30%) free of 148 GB
Total RAM: 3000 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:36:36, on 29.4.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16773)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Ruzne programy\Winamp\winampa.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxext.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Ruzne programy\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Canon\My Image Garden\cnmigmain.exe
C:\Windows\explorer.exe
C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\sosna\AppData\Roaming\uTorrent\updates\3.4.6_42094\utorrentie.exe
C:\Users\sosna\AppData\Roaming\uTorrent\updates\3.4.6_42094\utorrentie.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\Downloads\RSIT.exe
C:\Program Files\trend micro\sosna.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Ruzne programy\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Ruzne programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 12967 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineUA1d0403c48accce0.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\User_Feed_Synchronization-{91A658F1-6916-485F-A9A7-2BA80CAC3873}.job - C:\Windows\system32\msfeedssync.exe sync
=========Mozilla firefox=========
ProfilePath - C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "gemgecko@gemius.com:1.02, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.2.5.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.73.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.73.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(11)
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\searchplugins\
inbox-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2015-09-24 68504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-20 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14 142896]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"BkupTray"=C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-04-10 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-04-10 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-04-18 167936]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-13 6183456]
"Skytel"=C:\Windows\Skytel.exe [2007-11-21 1826816]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-09-11 809480]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-05-14 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-06-11 409600]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"WinampAgent"=C:\Ruzne programy\Winamp\winampa.exe [2008-08-04 36352]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2015-03-02 2477056]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2014-01-17 1284680]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2014-01-15 438888]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2016-01-29 594992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Ruzne programy\DAEMON Tools\daemon.exe [2007-08-29 171464]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-02 21644384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-04-15 6675672]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"cz.seznam.software.autoupdate"=C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"uTorrent"=C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe [2016-04-07 1959424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.tscc"=tsccvid.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-04-29 18:02:11 ----D---- C:\AdwCleaner
2016-04-29 16:56:04 ----D---- C:\Program Files\trend micro
2016-04-29 16:56:03 ----D---- C:\rsit
2016-04-28 05:07:59 ----D---- C:\Program Files\Mozilla Firefox
2016-04-17 03:48:28 ----A---- C:\Windows\system32\msxml3.dll
2016-04-17 03:45:50 ----A---- C:\Windows\system32\ncrypt.dll
2016-04-17 03:45:43 ----A---- C:\Windows\system32\secur32.dll
2016-04-17 03:45:41 ----A---- C:\Windows\system32\samlib.dll
2016-04-17 03:45:39 ----A---- C:\Windows\system32\samsrv.dll
2016-04-17 03:45:36 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-17 03:43:23 ----A---- C:\Windows\system32\tzres.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\ole32.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\kernel32.dll
2016-04-17 03:18:16 ----A---- C:\Windows\system32\ntdll.dll
2016-04-17 03:09:40 ----A---- C:\Windows\system32\msorcl32.dll
2016-04-17 03:09:39 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-17 03:08:33 ----A---- C:\Windows\system32\win32k.sys
2016-04-16 13:32:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\urlmon.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\mshta.exe
2016-04-16 13:32:36 ----A---- C:\Windows\system32\msfeedssync.exe
2016-04-16 13:32:35 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-16 13:32:35 ----A---- C:\Windows\system32\jsproxy.dll
2016-04-16 13:32:34 ----A---- C:\Windows\system32\ieUnatt.exe
2016-04-16 13:32:33 ----A---- C:\Windows\system32\iertutil.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\url.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\dxtmsft.dll
2016-04-16 13:32:30 ----A---- C:\Windows\system32\ieframe.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\wininet.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\vbscript.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\ieui.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-16 13:32:22 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-16 13:32:21 ----A---- C:\Windows\system32\jscript.dll
2016-04-16 13:32:17 ----A---- C:\Windows\system32\mshtml.dll
2016-04-16 13:32:14 ----A---- C:\Windows\system32\jscript9.dll
2016-04-07 17:18:37 ----D---- C:\Users\sosna\AppData\Roaming\uTorrent
======List of files/folders modified in the last 1 month======
2016-04-29 19:36:22 ----D---- C:\Windows\temp
2016-04-29 18:30:15 ----D---- C:\Users\sosna\AppData\Roaming\Seznam.cz
2016-04-29 18:29:36 ----D---- C:\Windows\System32
2016-04-29 18:29:36 ----D---- C:\Windows\inf
2016-04-29 18:29:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 18:26:19 ----D---- C:\Users\sosna\AppData\Roaming\Skype
2016-04-29 18:13:46 ----D---- C:\Windows
2016-04-29 16:56:04 ----RD---- C:\Program Files
2016-04-28 07:33:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-27 07:08:30 ----D---- C:\Program Files\CCleaner
2016-04-27 04:12:53 ----SHD---- C:\System Volume Information
2016-04-22 18:39:34 ----D---- C:\ProgramData\CanonIJPLM
2016-04-21 15:05:04 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 08:45:23 ----D---- C:\Windows\Debug
2016-04-17 17:59:51 ----D---- C:\Program Files\ZbrojniPrukaz
2016-04-17 04:31:14 ----D---- C:\Windows\rescache
2016-04-17 04:06:26 ----D---- C:\Windows\system32\sk-SK
2016-04-17 04:06:26 ----D---- C:\Windows\system32\migration
2016-04-17 04:06:25 ----D---- C:\Program Files\Internet Explorer
2016-04-17 03:50:40 ----SHD---- C:\Windows\Installer
2016-04-17 03:50:31 ----D---- C:\ProgramData\Microsoft Help
2016-04-17 03:48:56 ----D---- C:\Windows\winsxs
2016-04-17 03:48:53 ----D---- C:\Windows\system32\catroot
2016-04-17 03:46:53 ----D---- C:\Windows\system32\catroot2
2016-04-17 03:39:34 ----D---- C:\Windows\system32\MRT
2016-04-17 03:36:38 ----D---- C:\Windows\Microsoft.NET
2016-04-17 03:29:20 ----RSD---- C:\Windows\assembly
2016-04-17 03:22:05 ----A---- C:\Windows\system32\mrt.exe
2016-04-17 03:08:12 ----D---- C:\Windows\system32\XPSViewer
2016-04-08 19:16:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 18:21:12 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-03-17 71488]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-05-14 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-04 685816]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-03-17 206312]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-20 146024]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-03-17 152728]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-03-17 44608]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-10-28 5632]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2015-11-20 111040]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-03-21 15392]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-05-14 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-05-14 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-29 952832]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2007-04-13 16384]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2007-03-13 9856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-06-14 2152344]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-31 14848]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2012-03-29 47360]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-08-12 61440]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-25 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 abn2srox;abn2srox; C:\Windows\system32\drivers\abn2srox.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 catchme;catchme; \??\C:\Users\sosna\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 ICDUSB2;Sony IC Recorder (P); C:\Windows\System32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-21 654336]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-05-14 500784]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-03-17 1983264]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxcr_device;lxcr_device; C:\Windows\system32\lxcrcoms.exe [2006-12-11 537520]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 eins2038;Eset install launcher (20382); C:\Windows\eins2038.dll,RDServiceStart eins2038 C:\Users\sosna\AppData\Local\Temp\inxE834.tmp []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08 269504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-28 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119492
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu, dochází k zasekávání počítače
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA1d0403c48accce0.job
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
:services
abn2srox
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
-
- Návštěvník
- Příspěvky: 60
- Registrován: 01 srp 2006 11:54
Re: Prosím o kontrolu, dochází k zasekávání počítače
Logfile of random's system information tool 1.10 (written by random/random)
Run by sosna at 2016-04-29 19:51:51
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 44 GB (30%) free of 148 GB
Total RAM: 3000 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:53:30, on 29.4.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16773)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Ruzne programy\Winamp\winampa.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Windows\system32\igfxext.exe
C:\Ruzne programy\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\sosna\Downloads\RSIT.exe
C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\trend micro\sosna.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Ruzne programy\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Ruzne programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 12479 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\User_Feed_Synchronization-{91A658F1-6916-485F-A9A7-2BA80CAC3873}.job - C:\Windows\system32\msfeedssync.exe sync
=========Mozilla firefox=========
ProfilePath - C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "gemgecko@gemius.com:1.02, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.2.5.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.73.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.73.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(11)
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\searchplugins\
inbox-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2015-09-24 68504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-20 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14 142896]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"BkupTray"=C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-04-10 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-04-10 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-04-18 167936]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-13 6183456]
"Skytel"=C:\Windows\Skytel.exe [2007-11-21 1826816]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-09-11 809480]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-05-14 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-06-11 409600]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"WinampAgent"=C:\Ruzne programy\Winamp\winampa.exe [2008-08-04 36352]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2015-03-02 2477056]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2014-01-17 1284680]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2014-01-15 438888]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Ruzne programy\DAEMON Tools\daemon.exe [2007-08-29 171464]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-02 21644384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-04-15 6675672]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"cz.seznam.software.autoupdate"=C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"uTorrent"=C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe [2016-04-07 1959424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.tscc"=tsccvid.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-04-29 19:44:47 ----D---- C:\_OTM
2016-04-29 18:02:11 ----D---- C:\AdwCleaner
2016-04-29 16:56:04 ----D---- C:\Program Files\trend micro
2016-04-29 16:56:03 ----D---- C:\rsit
2016-04-28 05:07:59 ----D---- C:\Program Files\Mozilla Firefox
2016-04-17 03:48:28 ----A---- C:\Windows\system32\msxml3.dll
2016-04-17 03:45:50 ----A---- C:\Windows\system32\ncrypt.dll
2016-04-17 03:45:43 ----A---- C:\Windows\system32\secur32.dll
2016-04-17 03:45:41 ----A---- C:\Windows\system32\samlib.dll
2016-04-17 03:45:39 ----A---- C:\Windows\system32\samsrv.dll
2016-04-17 03:45:36 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-17 03:43:23 ----A---- C:\Windows\system32\tzres.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\ole32.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\kernel32.dll
2016-04-17 03:18:16 ----A---- C:\Windows\system32\ntdll.dll
2016-04-17 03:09:40 ----A---- C:\Windows\system32\msorcl32.dll
2016-04-17 03:09:39 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-17 03:08:33 ----A---- C:\Windows\system32\win32k.sys
2016-04-16 13:32:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\urlmon.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\mshta.exe
2016-04-16 13:32:36 ----A---- C:\Windows\system32\msfeedssync.exe
2016-04-16 13:32:35 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-16 13:32:35 ----A---- C:\Windows\system32\jsproxy.dll
2016-04-16 13:32:34 ----A---- C:\Windows\system32\ieUnatt.exe
2016-04-16 13:32:33 ----A---- C:\Windows\system32\iertutil.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\url.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\dxtmsft.dll
2016-04-16 13:32:30 ----A---- C:\Windows\system32\ieframe.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\wininet.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\vbscript.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\ieui.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-16 13:32:22 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-16 13:32:21 ----A---- C:\Windows\system32\jscript.dll
2016-04-16 13:32:17 ----A---- C:\Windows\system32\mshtml.dll
2016-04-16 13:32:14 ----A---- C:\Windows\system32\jscript9.dll
2016-04-07 17:18:37 ----D---- C:\Users\sosna\AppData\Roaming\uTorrent
======List of files/folders modified in the last 1 month======
2016-04-29 19:51:48 ----D---- C:\Windows\temp
2016-04-29 19:51:07 ----D---- C:\Users\sosna\AppData\Roaming\Skype
2016-04-29 19:44:58 ----D---- C:\Windows\Tasks
2016-04-29 18:30:15 ----D---- C:\Users\sosna\AppData\Roaming\Seznam.cz
2016-04-29 18:29:36 ----D---- C:\Windows\System32
2016-04-29 18:29:36 ----D---- C:\Windows\inf
2016-04-29 18:29:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 18:13:46 ----D---- C:\Windows
2016-04-29 16:56:04 ----RD---- C:\Program Files
2016-04-28 07:33:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-27 07:08:30 ----D---- C:\Program Files\CCleaner
2016-04-27 04:12:53 ----SHD---- C:\System Volume Information
2016-04-22 18:39:34 ----D---- C:\ProgramData\CanonIJPLM
2016-04-21 15:05:04 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 08:45:23 ----D---- C:\Windows\Debug
2016-04-17 17:59:51 ----D---- C:\Program Files\ZbrojniPrukaz
2016-04-17 04:31:14 ----D---- C:\Windows\rescache
2016-04-17 04:06:26 ----D---- C:\Windows\system32\sk-SK
2016-04-17 04:06:26 ----D---- C:\Windows\system32\migration
2016-04-17 04:06:25 ----D---- C:\Program Files\Internet Explorer
2016-04-17 03:50:40 ----SHD---- C:\Windows\Installer
2016-04-17 03:50:31 ----D---- C:\ProgramData\Microsoft Help
2016-04-17 03:48:56 ----D---- C:\Windows\winsxs
2016-04-17 03:48:53 ----D---- C:\Windows\system32\catroot
2016-04-17 03:46:53 ----D---- C:\Windows\system32\catroot2
2016-04-17 03:39:34 ----D---- C:\Windows\system32\MRT
2016-04-17 03:36:38 ----D---- C:\Windows\Microsoft.NET
2016-04-17 03:29:20 ----RSD---- C:\Windows\assembly
2016-04-17 03:22:05 ----A---- C:\Windows\system32\mrt.exe
2016-04-17 03:08:12 ----D---- C:\Windows\system32\XPSViewer
2016-04-08 19:16:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 18:21:12 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-03-17 71488]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-05-14 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-04 685816]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-03-17 206312]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-20 146024]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-03-17 152728]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-03-17 44608]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-10-28 5632]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2015-11-20 111040]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-03-21 15392]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-05-14 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-05-14 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-29 952832]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2007-04-13 16384]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2007-03-13 9856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-06-14 2152344]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-31 14848]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2012-03-29 47360]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-08-12 61440]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-25 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 amm5naw3;amm5naw3; C:\Windows\system32\drivers\amm5naw3.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 catchme;catchme; \??\C:\Users\sosna\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 ICDUSB2;Sony IC Recorder (P); C:\Windows\System32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-21 654336]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-05-14 500784]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-03-17 1983264]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxcr_device;lxcr_device; C:\Windows\system32\lxcrcoms.exe [2006-12-11 537520]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 eins2038;Eset install launcher (20382); C:\Windows\eins2038.dll,RDServiceStart eins2038 C:\Users\sosna\AppData\Local\Temp\inxE834.tmp []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08 269504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-28 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
Run by sosna at 2016-04-29 19:51:51
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 44 GB (30%) free of 148 GB
Total RAM: 3000 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:53:30, on 29.4.2016
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16773)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\sosna\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Ruzne programy\Winamp\winampa.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Windows\system32\igfxext.exe
C:\Ruzne programy\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\sosna\Downloads\RSIT.exe
C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
C:\Program Files\Canon\Quick Menu\CNQMSWCS.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\trend micro\sosna.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [ProductReg] "C:\Program Files\Acer\WR_PopUp\ProductReg.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Ruzne programy\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Ruzne programy\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [uTorrent] "C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.8.0_73\bin\jp2iexp.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcr_device - - C:\Windows\system32\lxcrcoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 12479 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\User_Feed_Synchronization-{91A658F1-6916-485F-A9A7-2BA80CAC3873}.job - C:\Windows\system32\msfeedssync.exe sync
=========Mozilla firefox=========
ProfilePath - C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default
prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "gemgecko@gemius.com:1.02, {a1e75a0e-4397-4ba8-bb50-e19fb66890f4}:3.2.5.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 21.0.0.213 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.73.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.73.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
NPOFF12.DLL
nppdf32.dll
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\extensions\
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}(11)
C:\Users\sosna\AppData\Roaming\Mozilla\Firefox\Profiles\w8jc0ziw.default\searchplugins\
inbox-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2015-09-24 68504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-20 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
ShowBarObj Class - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll [2008-05-14 312880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-20 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll [2008-05-14 142896]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-25 1049896]
"BkupTray"=C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [2008-04-06 34040]
"ArcadeDeluxeAgent"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2008-04-10 147456]
"CLMLServer"=C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [2008-04-10 167936]
"PlayMovie"=C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2008-04-18 167936]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-06-13 6183456]
"Skytel"=C:\Windows\Skytel.exe [2007-11-21 1826816]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2008-09-11 809480]
"eDataSecurity Loader"=C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [2008-05-14 526896]
"ePower_DMC"=C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [2008-06-11 409600]
"ProductReg"=C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]
"WinampAgent"=C:\Ruzne programy\Winamp\winampa.exe [2008-08-04 36352]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2015-03-02 2477056]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdSync.exe [2008-01-21 215552]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"CanonQuickMenu"=C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [2014-01-17 1284680]
"IJNetworkScannerSelectorEX"=C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2014-01-15 438888]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Ruzne programy\DAEMON Tools\daemon.exe [2007-08-29 171464]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-07-02 21644384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2016-04-15 6675672]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"cz.seznam.software.autoupdate"=C:\Users\sosna\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\sosna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"uTorrent"=C:\Users\sosna\AppData\Roaming\uTorrent\uTorrent.exe [2016-04-07 1959424]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"vidc.tscc"=tsccvid.dll
"msacm.siren"=sirenacm.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-04-29 19:44:47 ----D---- C:\_OTM
2016-04-29 18:02:11 ----D---- C:\AdwCleaner
2016-04-29 16:56:04 ----D---- C:\Program Files\trend micro
2016-04-29 16:56:03 ----D---- C:\rsit
2016-04-28 05:07:59 ----D---- C:\Program Files\Mozilla Firefox
2016-04-17 03:48:28 ----A---- C:\Windows\system32\msxml3.dll
2016-04-17 03:45:50 ----A---- C:\Windows\system32\ncrypt.dll
2016-04-17 03:45:43 ----A---- C:\Windows\system32\secur32.dll
2016-04-17 03:45:41 ----A---- C:\Windows\system32\samlib.dll
2016-04-17 03:45:39 ----A---- C:\Windows\system32\samsrv.dll
2016-04-17 03:45:36 ----A---- C:\Windows\system32\lsasrv.dll
2016-04-17 03:43:23 ----A---- C:\Windows\system32\tzres.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\ole32.dll
2016-04-17 03:18:17 ----A---- C:\Windows\system32\kernel32.dll
2016-04-17 03:18:16 ----A---- C:\Windows\system32\ntdll.dll
2016-04-17 03:09:40 ----A---- C:\Windows\system32\msorcl32.dll
2016-04-17 03:09:39 ----A---- C:\Windows\system32\mtxoci.dll
2016-04-17 03:08:33 ----A---- C:\Windows\system32\win32k.sys
2016-04-16 13:32:37 ----A---- C:\Windows\system32\msfeedsbs.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\urlmon.dll
2016-04-16 13:32:36 ----A---- C:\Windows\system32\mshta.exe
2016-04-16 13:32:36 ----A---- C:\Windows\system32\msfeedssync.exe
2016-04-16 13:32:35 ----A---- C:\Windows\system32\msfeeds.dll
2016-04-16 13:32:35 ----A---- C:\Windows\system32\jsproxy.dll
2016-04-16 13:32:34 ----A---- C:\Windows\system32\ieUnatt.exe
2016-04-16 13:32:33 ----A---- C:\Windows\system32\iertutil.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\url.dll
2016-04-16 13:32:32 ----A---- C:\Windows\system32\dxtmsft.dll
2016-04-16 13:32:30 ----A---- C:\Windows\system32\ieframe.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\wininet.dll
2016-04-16 13:32:27 ----A---- C:\Windows\system32\vbscript.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\ieui.dll
2016-04-16 13:32:26 ----A---- C:\Windows\system32\dxtrans.dll
2016-04-16 13:32:22 ----A---- C:\Windows\system32\mshtmled.dll
2016-04-16 13:32:21 ----A---- C:\Windows\system32\jscript.dll
2016-04-16 13:32:17 ----A---- C:\Windows\system32\mshtml.dll
2016-04-16 13:32:14 ----A---- C:\Windows\system32\jscript9.dll
2016-04-07 17:18:37 ----D---- C:\Users\sosna\AppData\Roaming\uTorrent
======List of files/folders modified in the last 1 month======
2016-04-29 19:51:48 ----D---- C:\Windows\temp
2016-04-29 19:51:07 ----D---- C:\Users\sosna\AppData\Roaming\Skype
2016-04-29 19:44:58 ----D---- C:\Windows\Tasks
2016-04-29 18:30:15 ----D---- C:\Users\sosna\AppData\Roaming\Seznam.cz
2016-04-29 18:29:36 ----D---- C:\Windows\System32
2016-04-29 18:29:36 ----D---- C:\Windows\inf
2016-04-29 18:29:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-04-29 18:13:46 ----D---- C:\Windows
2016-04-29 16:56:04 ----RD---- C:\Program Files
2016-04-28 07:33:31 ----D---- C:\Program Files\Mozilla Maintenance Service
2016-04-27 07:08:30 ----D---- C:\Program Files\CCleaner
2016-04-27 04:12:53 ----SHD---- C:\System Volume Information
2016-04-22 18:39:34 ----D---- C:\ProgramData\CanonIJPLM
2016-04-21 15:05:04 ----N---- C:\Windows\system32\MpSigStub.exe
2016-04-21 08:45:23 ----D---- C:\Windows\Debug
2016-04-17 17:59:51 ----D---- C:\Program Files\ZbrojniPrukaz
2016-04-17 04:31:14 ----D---- C:\Windows\rescache
2016-04-17 04:06:26 ----D---- C:\Windows\system32\sk-SK
2016-04-17 04:06:26 ----D---- C:\Windows\system32\migration
2016-04-17 04:06:25 ----D---- C:\Program Files\Internet Explorer
2016-04-17 03:50:40 ----SHD---- C:\Windows\Installer
2016-04-17 03:50:31 ----D---- C:\ProgramData\Microsoft Help
2016-04-17 03:48:56 ----D---- C:\Windows\winsxs
2016-04-17 03:48:53 ----D---- C:\Windows\system32\catroot
2016-04-17 03:46:53 ----D---- C:\Windows\system32\catroot2
2016-04-17 03:39:34 ----D---- C:\Windows\system32\MRT
2016-04-17 03:36:38 ----D---- C:\Windows\Microsoft.NET
2016-04-17 03:29:20 ----RSD---- C:\Windows\assembly
2016-04-17 03:22:05 ----A---- C:\Windows\system32\mrt.exe
2016-04-17 03:08:12 ----D---- C:\Windows\system32\XPSViewer
2016-04-08 19:16:29 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2016-04-06 18:21:12 ----D---- C:\Windows\Minidump
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-03-17 71488]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2008-05-14 18992]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-04 685816]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-31 13824]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-03-17 206312]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-11-20 146024]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-03-17 152728]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-03-17 44608]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-10-28 5632]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-04-18 61424]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2015-11-20 111040]
R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-03-21 15392]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2008-01-21 95744]
R2 NTIPPKernel;NTIPPKernel; \??\C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 PSDNServ;PSDNServ; C:\Windows\system32\DRIVERS\PSDNServ.sys [2008-05-14 16944]
R2 psdvdisk;PSDVdisk; C:\Windows\system32\DRIVERS\PSDVdisk.sys [2008-05-14 60464]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-03-01 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-12-29 952832]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-03 21264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2007-04-13 16384]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2007-03-13 9856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2011-02-11 9036800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-06-14 2152344]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-31 14848]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2012-03-29 47360]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-08-12 61440]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-25 199472]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2013-07-12 134272]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-21 299008]
S3 amm5naw3;amm5naw3; C:\Windows\system32\drivers\amm5naw3.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-01-21 179712]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 catchme;catchme; \??\C:\Users\sosna\AppData\Local\Temp\catchme.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2008-01-21 987648]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2008-01-21 200704]
S3 ICDUSB2;Sony IC Recorder (P); C:\Windows\System32\Drivers\ICDUSB2.sys [2002-11-28 39048]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2011-08-17 18176]
S3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-21 30720]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2013-07-12 73344]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2008-01-21 654336]
S3 winusb;WinUSB Service; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-12-14 82128]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2008-03-18 13312]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 eDataSecurity Service;eDataSecurity Service; C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [2008-05-14 500784]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-03-17 1983264]
R2 ETService;Empowering Technology Service; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
R2 lxcr_device;lxcr_device; C:\Windows\system32\lxcrcoms.exe [2006-12-11 537520]
R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2007-12-06 110592]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2014-04-12 772296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 eins2038;Eset install launcher (20382); C:\Windows\eins2038.dll,RDServiceStart eins2038 C:\Users\sosna\AppData\Local\Temp\inxE834.tmp []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-04-08 269504]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-09-07 144200]
S3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [2015-12-02 235696]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2016-04-28 146888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119492
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Prosím o kontrolu, dochází k zasekávání počítače
Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.