
ComboFix 10-02-12.01 - Marushka 17.02.2010 20:00:27.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2046.1079 [GMT 1:00]
Spuštěný z: c:\users\Marushka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Marushka\Desktop\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AVG\AVG9\Toolbar
c:\program files\AVG\AVG9\Toolbar\Firefox\39_sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\40_sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\48_sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\autocomplete.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\avgapi.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils.xpt
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\notifications.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgdatabaseversion.xpt
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgprogramversion.xpt
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgsearchratingsconfig.xpt
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.xpt
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\config.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\html\tabswelcome.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\html\tabswelcome_ie7header.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\content\Languages\en.ini
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\chrome\skin\searchProvider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_23\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\config.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\html\tabswelcome.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\html\tabswelcome_ie7header.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\content\Languages\en.ini
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\skin\searchProvider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\chrome\skin\spGeneralSearch.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_39\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\config.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\html\tabswelcome.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\html\tabswelcome_ie7header.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\content\Languages\en.ini
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\skin\searchProvider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\chrome\skin\spYandex.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_40\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\config.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\html\tabswelcome.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\html\tabswelcome_ie7header.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\content\Languages\en.ini
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\skin\searchProvider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\chrome\skin\spBaidu.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\ch_48\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\channels.dat
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome.manifest
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\after_install.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\after_uninstall.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\autocomplete-popup.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\avg\avgtbapi.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\avg\customwrapper.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\avg\partFiles.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\avg\statusindicator.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\config.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\config.xml.old
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\contexthtml.xul
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\custom.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\ex\marquee.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\about.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_AB.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_ABSearch.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_arrow.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_bottom_shadow.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirm.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmAVGSafe.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_confirmTbr.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_general.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_IDV.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_IDV1.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_IDV2.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_logo.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_protection.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_search.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBox.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBoxBaidu.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_searchSearchBoxBlank.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_SPupdate.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_SPupdateSearchBox.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_style.css
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\bubble_top_shadow.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\deletehistory_processing.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBAccess.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBCalc.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBExcel.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBExplorer.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBMediaPlayer.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBNotepad.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBOutlook.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBOutlookExpress.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBPaint.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBPowerPoint.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\icoUBWord.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!backgroundGrey.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!backgroundRed.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!bullet.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!close.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoiDNES.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoRead.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoRSS.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoSimple.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!icoUnread.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!logo.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!settings.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_!tabHilighted.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_advanced.css
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_advanced.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_config.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\rssreader_simple.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_askdialog.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_background.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_closedialog.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_checkboxdialog.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icohelp.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoQuest.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoRisk.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoSafe.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_icoUnkn.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_loading.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_logo.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_main.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu1.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu2.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu3.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_menu4.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\settings_style.css
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome.htm.old
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_button.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_button_hilight.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_buttonHilight.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7footer.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7header.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_ie7header.htm.old
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_poweredByBlank.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tabswelcome_poweredByYahoo.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\tbapi.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\toolbarprotector_window.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_error.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_ok.gif
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\html\updater_processing.htm
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\htmlwindow.xul
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\imageButton.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\Languages\en.ini
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\Languages\en.ini.old
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\Languages\languages.cfg
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\bubbles.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\cache.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\cookie.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\directory.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\dns.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\dom.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\dragdrop.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\file.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\chevron.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\include.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\include_lite.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\loader.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\log.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\mutex.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\newtab.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\pass.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\prefs.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\privacy.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\refreshControl.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\registry.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\resources.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\searches.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\searchplugin.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\searchProvs.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\settings.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\splitter.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\stats.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\tabs.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\translation.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\update.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\updatecontrol.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\updateext.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\updater.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\updates.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\usefulbuttons.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\utils.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\visibility.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\wrapper.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\xml.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\xmlconfig.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libs\xmlitems.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\mail.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\mime.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\pop3.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\rss.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\ticker.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\libsex\xmlitemsex.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\overlay.js
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\overlay.xul
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\content\searchProviders.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\icons\default\htmlwindow.ico
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\contexthtml.css
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\dragdrop.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\gripper.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\chevron.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoAbout.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoAVGInfo.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoGoButtonBG.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoHomepage.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoIdentityGuard.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoNoProtection.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoOptions.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoProtection.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoProtectionLimited.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSS.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSBlue.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSGray.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoRSSGreen.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoTrash.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBAccess.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBCalc.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBExcel.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBExplorer.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBMediaPlayer.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBNotepad.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBOutlook.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBOutlookExpress.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBPaint.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBPowerPoint.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUBWord.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\icoUpdate.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\logo.ico
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\logo.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\overlay.css
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\rssreader_!icoRead.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\rssreader_!icoUnread.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\Search_provider_drop.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\searchprovider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\searchprovider.png.old
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\settings_icon.ico
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\slider.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spgeneralsearch.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spImages.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spLocal.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spShopping.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spVideo.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spWiki.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spYahoo.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spYahooBG.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\spYahooBG_small.png
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\chrome\skin\toolbarprotector_icon.ico
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\install.rdf
c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\sp.xml
c:\program files\AVG\AVG9\Toolbar\Firefox\sp.xml.old
c:\program files\AVG\AVG9\Toolbar\IE8Lib.dll
c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\Yahoo!
c:\program files\Yahoo!\common\unyt.exe
c:\program files\Yahoo!\Companion\Data\dlg_as.html
c:\program files\Yahoo!\Companion\Data\dlg_atb.html
c:\program files\Yahoo!\Companion\Data\dlg_catb.html
c:\program files\Yahoo!\Companion\Data\dlg_cnf.html
c:\program files\Yahoo!\Companion\Data\dlg_cotb.html
c:\program files\Yahoo!\Companion\Data\dlg_ctb.html
c:\program files\Yahoo!\Companion\Data\dlg_map.html
c:\program files\Yahoo!\Companion\Data\dlg_opt.html
c:\program files\Yahoo!\Companion\Data\dlg_pub.html
c:\program files\Yahoo!\Companion\Data\dlg_upg.html
c:\program files\Yahoo!\Companion\Data\dlg_wp2.html
c:\program files\Yahoo!\Companion\Installs\cpn\pubmod.dll
c:\program files\Yahoo!\Companion\Installs\cpn\YMERemote.dll
c:\program files\Yahoo!\Companion\Installs\cpn\ypubc.dll
c:\program files\Yahoo!\Companion\Installs\cpn\yt.dll
c:\program files\Yahoo!\Companion\Installs\cpn\YTabBar.dll
c:\program files\Yahoo!\Companion\Installs\cpn\YTAntiSpy.dll
c:\program files\Yahoo!\Companion\Installs\cpn\ytinst.log
c:\program files\Yahoo!\Companion\Installs\cpn\YTMsgr.dll
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-17 do 2010-02-17 )))))))))))))))))))))))))))))))
.
2010-02-17 19:07 . 2010-02-17 19:11 -------- d-----w- c:\users\Marushka\AppData\Local\temp
2010-02-17 19:07 . 2010-02-17 19:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-17 19:07 . 2010-02-17 19:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-17 15:05 . 2010-02-17 15:11 -------- d-----w- c:\program files\trend micro
2010-02-17 15:05 . 2010-02-17 15:11 -------- d-----w- C:\rsit
2010-02-16 23:14 . 2010-02-16 23:14 -------- d-----w- c:\users\Marushka\AppData\Roaming\Malwarebytes
2010-02-16 23:14 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-16 23:14 . 2010-02-16 23:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-16 23:14 . 2010-02-16 23:14 -------- d-----w- c:\programdata\Malwarebytes
2010-02-16 23:14 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 11:32 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-10 11:32 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-07 14:01 . 2010-02-07 14:01 -------- d-----w- c:\users\Marushka\AppData\Roaming\Facebook
2010-02-07 11:25 . 2010-02-07 11:26 -------- d-----w- c:\users\Marushka\AppData\Roaming\Zoner
2010-02-07 11:24 . 2010-02-07 11:24 -------- d-----w- c:\program files\Zoner
2010-02-03 16:08 . 2010-02-03 17:25 -------- d-----w- c:\program files\EA GAMES
2010-02-03 16:08 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2010-01-22 10:57 . 2009-12-16 11:44 834048 ----a-w- c:\windows\system32\wininet.dll
2010-01-22 10:57 . 2009-12-18 13:01 78336 ----a-w- c:\windows\system32\ieencode.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 19:12 . 2009-11-01 17:05 -------- d-----w- c:\users\Marushka\AppData\Roaming\skypePM
2010-02-17 19:07 . 2008-12-27 02:09 7525 ----a-w- c:\windows\bthservsdp.dat
2010-02-17 15:23 . 2009-12-03 12:19 0 ----a-w- c:\users\Marushka\AppData\Local\prvlcl.dat
2010-02-16 20:33 . 2007-01-08 21:09 649178 ----a-w- c:\windows\system32\perfh005.dat
2010-02-16 20:33 . 2007-01-08 21:09 143998 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 21:22 . 2010-01-06 00:18 -------- d-----w- c:\users\Marushka\AppData\Roaming\uTorrent
2010-02-11 02:25 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-07 14:01 . 2010-02-07 14:01 50354 ----a-w- c:\users\Marushka\AppData\Roaming\Facebook\uninstall.exe
2010-02-01 22:04 . 2010-02-01 22:04 847040 ----a-w- c:\users\Marushka\AppData\Roaming\Facebook\axfbootloader.dll
2010-02-01 22:04 . 2010-02-01 22:04 5578752 ----a-w- c:\users\Marushka\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
2010-01-28 11:55 . 2008-12-30 15:27 28124 ----a-w- c:\users\Marushka\AppData\Roaming\nvModes.dat
2010-01-23 01:30 . 2009-10-18 17:04 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-21 19:58 . 2009-11-01 17:04 -------- d-----w- c:\users\Marushka\AppData\Roaming\Skype
2010-01-07 19:45 . 2010-01-04 21:23 -------- d-----w- c:\users\Marushka\AppData\Roaming\BSplayer
2010-01-06 00:17 . 2010-01-06 00:18 697965 ----a-w- c:\users\Marushka\AppData\Roaming\uTorrent\unins000.exe
2010-01-04 21:23 . 2010-01-04 21:23 -------- d-----w- c:\users\Marushka\AppData\Roaming\BSplayer Pro
2010-01-04 21:23 . 2010-01-04 21:23 -------- d-----w- c:\program files\Webteh
2010-01-01 19:18 . 2009-12-20 20:17 -------- d-----w- c:\program files\ICQ6.5
2009-12-22 23:29 . 2009-06-28 17:36 -------- d-----w- c:\program files\Java
2009-12-20 20:18 . 2008-11-17 17:32 -------- d-----w- c:\programdata\ICQ
2009-12-20 20:18 . 2008-11-17 17:31 -------- d-----w- c:\program files\ICQ6
2009-12-11 11:43 . 2010-02-10 11:33 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 11:43 . 2010-02-10 11:33 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:01 . 2010-02-10 11:33 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:01 . 2010-02-10 11:33 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:01 . 2010-02-10 11:33 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 17:26 . 2010-02-10 11:33 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-12-04 18:30 . 2010-02-10 11:33 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-04 18:29 . 2010-02-10 11:33 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-04 18:28 . 2010-02-10 11:33 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-04 18:28 . 2010-02-10 11:33 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-04 18:28 . 2010-02-10 11:33 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-04 18:28 . 2010-02-10 11:33 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-04 18:28 . 2010-02-10 11:33 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-04 18:28 . 2010-02-10 11:33 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-04 18:27 . 2010-02-10 11:33 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-11-30 19:00 . 2010-01-06 00:18 289584 ----a-w- c:\users\Marushka\AppData\Roaming\uTorrent\utorrent.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Infium"="c:\program files\QIP Infium\infium.exe" [2009-03-19 5244928]
"Mobile Partner"="c:\program files\3 Internet\3 Internet.exe" [2009-06-23 110592]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-12-14 102400]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"eAudio"="c:\acer\Empowering Technology\eAudio\eAudio.exe" [2007-08-31 1286144]
"RtHDVCpl"="RtHDVCpl.exe" [2007-12-14 4702208]
"Skytel"="Skytel.exe" [2007-12-14 1826816]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-01-02 707080]
"MSPService"="c:\program files\Acer Arcade Deluxe\SportsCap\Kernel\MagicSports\MSPMirage.exe" [2007-02-13 102400]
"TVEService"="c:\program files\Acer Arcade Deluxe\TV Joy\TVEService.exe" [2007-07-27 151552]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-12-05 200704]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-14 8501792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-14 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-11-10 1216512]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-12-26 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):4c,07,96,e2,0a,04,ca,01
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [31.10.2009 15:37 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\drivers\avgtdix.sys [31.10.2009 15:37 360584]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [10.11.2008 15:36 41456]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [31.10.2009 15:36 285392]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [10.11.2008 15:44 233472]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVECapSvc.exe [10.11.2008 15:36 286820]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVESched.exe [10.11.2008 15:36 110682]
R3 A310;AVerMedia A310 DVB-T;c:\windows\System32\drivers\AVerA310USB.sys [10.11.2008 23:28 26752]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\System32\drivers\AVerA310Cap.sys [10.11.2008 23:28 42752]
R3 winbondcir;Winbond IR Transceiver;c:\windows\System32\drivers\winbondcir.sys [26.12.2007 13:35 43008]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [26.12.2007 13:35 179712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Marushka\AppData\Roaming\Mozilla\Firefox\Profiles\e92r6x6i.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://cs.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:cs:official
FF - prefs.js: keyword.URL - hxxp://www.webhledani.cz/results.aspx?i=39&tp=ab&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Marushka\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-Yahoo! Companion - c:\progra~1\Yahoo!\common\unyt.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-17 20:11
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.exe'(4428)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
c:\windows\system32\btncopy.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\acer\Empowering Technology\eNet\eNet Service.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
c:\acer\Empowering Technology\ePower\ePowerSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Launch Manager\QtZgAcer.EXE
c:\windows\System32\rundll32.exe
c:\acer\Empowering Technology\ENET\ENMTRAY.EXE
c:\acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
c:\acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
c:\acer\Empowering Technology\eRecovery\ERAGENT.EXE
c:\users\Marushka\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Acer\Acer VCM\acp2HID.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\programdata\Skype\Plugins\Plugins\903CB56BA52F42478957BE8314837A86\PamelaPCR.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-02-17 20:18:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-17 19:18
ComboFix2.txt 2010-02-16 21:01
Před spuštěním: Volných bajtů: 63 555 829 760
Po spuštění: Volných bajtů: 63 460 511 744
- - End Of File - - 06B710A672AF11F5CB76A9AEEA4A7191