Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Kontrola logu

#1 Příspěvek od Guardian23 »

Dobrý den,

přijde mi, že počítač docela pomalu najíždí. Je pravda, že dlouho neprošel reinstalací. Ale po nalezení tohoto webu mě napadlo, jesti nemůže PC obsahovat malware apod.

Je-li to možné, prosím o kontrolu logu. Předem děkuji.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-11-30 09:00:38
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (6%) free of 50 GB
Total RAM: 2047 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:00:43, on 30.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Firebird\bin\fbserver.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\LiveZilla\LiveZilla.exe
D:\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QIP\qip.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator.LENKA\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [RelevantKnowledge] C:\program files\relevantknowledge\rlvknlg.exe -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [netmon.exe] C:\Program Files\netmon\netmon.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [LiveZilla] "C:\Program Files\LiveZilla\LiveZilla.exe" -minimize
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [systemz] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi ... p=ZJfox000
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/63.27/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0379200234
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - D:\nydecky.cz\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Služba inteligentního přenosu na pozadí (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KoopPdfService - Unknown owner - C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: MySQL - MySQL AB - D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Automatické aktualizace (wuauserv) - Unknown owner - C:\WINDOWS\
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.LEN/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 15946 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-1482476501-725345543-500Core1cb6cbda6e52066.job
C:\WINDOWS\tasks\Install.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IcePick_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_rundll32_exe.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
MyWebSearch Search Assistant BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL [2009-08-09 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
mwsBar BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2009-08-09 438367]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-10-24 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\SearchSettings.dll [2009-12-16 1109504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA} - My Web Search - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2009-08-09 438367]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"GBB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe [2006-07-12 356352]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-17 148888]
"MyWebSearch Plugin"=rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF []
"My Web Search Bar Search Scope Monitor"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe [2009-08-09 24688]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe [2009-08-09 32838]
"RelevantKnowledge"=C:\program files\relevantknowledge\rlvknlg.exe -boot []
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824]
"netmon.exe"=C:\Program Files\netmon\netmon.exe []
"SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2009-12-16 975360]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-03-16 47392]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-03-17 421888]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-03-12 119152]
"LiveZilla"=C:\Program Files\LiveZilla\LiveZilla.exe [2010-05-17 2651576]
"iTunesHelper"=D:\iTunes\iTunesHelper.exe [2010-07-21 141608]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-10-24 202256]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
"systemz"=C:\WINDOWS\system32\drivers\ctfmon.exe []
"Google Update"=C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe [2009-08-09 32838]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"QIP2005"=C:\Program Files\QIP\qip.exe [2008-12-09 3259392]

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Administrator.LENKA\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\GOOGLE\GOOGLE~3\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2009-07-20 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"E:\Hry\STALKER\bin\xrEngine.exe"="E:\Hry\STALKER\bin\xrEngine.exe:*:Enabled:Ń.Ň.Ŕ.Ë.Ę.Ĺ.Đ. - ×čńňîĺ Íĺáî (CLI)"
"E:\Hry\STALKER\bin\dedicated\xrEngine.exe"="E:\Hry\STALKER\bin\dedicated\xrEngine.exe:*:Enabled:Ń.Ň.Ŕ.Ë.Ę.Ĺ.Đ. - ×čńňîĺ Íĺáî (SRV)"
"C:\Program Files\bwin\StartbwinPoker.exe"="C:\Program Files\bwin\StartbwinPoker.exe:*:Enabled:StartbwinPoker.exe"
"D:\hl22\HALF LIFE 2\hl2.exe"="D:\hl22\HALF LIFE 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"E:\Hry\zh\game.dat"="E:\Hry\zh\game.dat:*:Enabled:game"
"G:\Crack\FlexLM\adskflex.exe"="G:\Crack\FlexLM\adskflex.exe:*:Enabled:adskflex"
"G:\Crack\FlexLM\lmgrd.exe"="G:\Crack\FlexLM\lmgrd.exe:*:Enabled:lmgrd"
"C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe"="C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe:*:Enabled:Kalk_ziv"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Autodesk\backburner\monitor.exe"="C:\Program Files\Autodesk\backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\backburner\manager.exe"="C:\Program Files\Autodesk\backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\backburner\server.exe"="C:\Program Files\Autodesk\backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Teamspeak2_RC2\server_windows.exe"="C:\Program Files\Teamspeak2_RC2\server_windows.exe:*:Enabled:Server"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"E:\Hry\Silverfall\Silverfall.exe"="E:\Hry\Silverfall\Silverfall.exe:*:Enabled:Silverfall"
"C:\Program Files\CrosuS\CrosuSApp.exe"="C:\Program Files\CrosuS\CrosuSApp.exe:*:Enabled:Crosus"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\iTunes\iTunes.exe"="D:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.js - edit -
.js - open -
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-11-29 21:28:16 ----D---- C:\Program Files\trend micro
2010-11-29 21:28:14 ----D---- C:\rsit
2010-11-29 19:27:21 ----A---- C:\WINDOWS\system32\drivers\AmdLLD.sys
2010-11-29 19:27:19 ----D---- C:\Program Files\AMD
2010-11-29 18:42:50 ----A---- C:\WINDOWS\system32\drivers\DrvAgent32.sys
2010-11-23 15:29:25 ----D---- C:\Program Files\Microsoft Silverlight
2010-11-05 15:43:18 ----D---- C:\Program Files\CamStudio
2010-10-31 14:48:19 ----A---- C:\WINDOWS\oodcnt.INI
2010-10-31 11:56:42 ----D---- C:\WINDOWS\system32\oodag
2010-10-31 10:00:37 ----D---- C:\Program Files\OO Software

======List of files/folders modified in the last 1 months======

2010-11-30 09:00:37 ----SD---- C:\WINDOWS\Tasks
2010-11-30 08:55:52 ----D---- C:\WINDOWS\Temp
2010-11-30 08:54:15 ----D---- C:\WINDOWS
2010-11-30 08:53:58 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-29 21:28:16 ----D---- C:\Program Files
2010-11-29 20:54:53 ----A---- C:\WINDOWS\wincmd.ini
2010-11-29 19:27:28 ----SHD---- C:\WINDOWS\Installer
2010-11-29 19:27:27 ----RSH---- C:\boot.ini
2010-11-29 19:27:25 ----HD---- C:\WINDOWS\inf
2010-11-29 19:27:25 ----D---- C:\WINDOWS\system32\drivers
2010-11-29 17:08:46 ----D---- C:\WINDOWS\system32
2010-11-26 13:45:45 ----D---- C:\Program Files\Simulace_2009
2010-11-25 18:48:33 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-11-23 15:29:34 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-11-22 15:36:13 ----D---- C:\Program Files\Mozilla Firefox
2010-11-22 15:36:02 ----A---- C:\WINDOWS\BRWMARK.INI
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Adobe
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Adobe
2010-11-19 15:15:07 ----D---- C:\Program Files\bwin
2010-11-18 17:17:27 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real
2010-11-18 17:17:20 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Real
2010-11-14 21:13:48 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Simulace_2009
2010-11-05 15:51:23 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-03 19:06:16 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-03 17:06:54 ----RSD---- C:\WINDOWS\assembly
2010-11-03 17:05:04 ----D---- C:\Program Files\AEGON Expert 2.0
2010-11-01 11:53:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CPC
2010-11-01 11:49:37 ----D---- C:\DATA_CPC
2010-10-31 23:48:20 ----D---- C:\Program Files\CPC
2010-10-31 10:02:17 ----D---- C:\WINDOWS\Help
2010-10-31 09:43:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-07-20 41728]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-11-20 43872]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-02-01 717296]
R1 avfwot;avfwot; C:\WINDOWS\system32\DRIVERS\avfwot.sys [2010-04-28 102856]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-04-28 124784]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-04-28 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-04-28 60936]
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 cpuz134;cpuz134; \??\C:\WINDOWS\system32\drivers\cpuz134_x32.sys []
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-18 88448]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-18 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-18 55936]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\WINDOWS\system32\DRIVERS\AVerBDA3x.sys [2006-12-14 1171456]
R3 avfwim;AvFw Packet Filter Miniport; C:\WINDOWS\system32\DRIVERS\avfwim.sys [2010-04-28 79432]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-22 17480]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-18 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-12 248192]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S1 seneka;seneka; C:\WINDOWS\system32\drivers\senekangvdknxf.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2010-03-12 30576]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023k.sys [2002-08-12 11136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirFirewallService;Avira FireWall; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [2010-04-28 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2010-04-28 337064]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-28 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-04-28 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-04-28 405672]
R2 Apache2.2;Apache2.2; D:\nydecky.cz\xampp\apache\bin\httpd.exe [2009-12-20 29416]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-23 77944]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-01-15 32256]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R2 KoopPdfService;KoopPdfService; C:\Program Files\Kooperativa\Services\KoopPDFServer.exe [2010-07-04 447488]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-03-12 139632]
R2 MySQL;MySQL; D:\nydecky.cz\xampp\mysql\bin\mysqld.exe [2009-12-20 6095504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2004-05-17 184320]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
S2 MyWebSearchService;My Web Search Service; C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe [2009-08-09 28762]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-11 68096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-22 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#2 Příspěvek od cernohous13 »

Vítám tě u nás Obrázek

Budeme čistit na etapy :wink:
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#3 Příspěvek od Guardian23 »

Děkuji za odpověď a přivítání.

Dle návodu spustím rychlý test, ale bohužel mi program vždy zamrzne po čase cca 1:30, 46.000 zkontrolovaných objektech (z toho 151 infikovaných) a na stejném souboru desktop.ini

Nějaký nápad, prosím? :turned:

------------EDIT------------
A ne, p.o.m.a.l.i.n.k.u. to jede. Tak snad se test zdárně dokončí.


------------Část 1------------
Malwarebytes' Anti-Malware 1.50
http://www.malwarebytes.org

Verze databáze: 5214

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

30.11.2010 12:44:31
logg.txt

Typ kontroly: Rychlý test
Testované objekty: 252986
Uplynulý čas: 2 hodin, 16 minut, 20 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 3
Infikované klíče v registru: 128
Infikované hodnoty v registru: 14
Infikované datové položky v registru: 2
Infikované složky: 48
Infikované soubory: 464

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> No action taken.

Infikované klíče v registru:
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.FunWebProducts) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seneka (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{67FA02C4-AB30-4e77-A640-78EE8EC8673B} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E3EF3BD5-02F3-4F99-9DAC-A20637DF084D}_is1 (Rogue.RegTool) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Plugin -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> No action taken.

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#4 Příspěvek od Guardian23 »

------------Část 2------------
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.

Infikované složky:
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\setups (Adware.MyWebSearch) -> No action taken.
c:\program files\regTool (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Email (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg\38 (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\pref (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plugins (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html (Rogue.RegTool) -> No action taken.
c:\program files\ThunMail (Trojan.Agent) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge (Spyware.MarketScore) -> No action taken.

Infikované soubory:
c:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\dealio toolbar\IE\4.0.2\dealiotoolbarie.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\all users.windows\Plocha\regTool.lnk (Rogue.RegTool) -> No action taken.
c:\tj.vbs (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekajwfoexno.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekangvdknxf.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekarmdcxeyp.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\ftp_non_crp.exe (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\service-466.exe (Trojan.Downloader) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator\avatar.dat (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator\zbucks.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\m3ntstbr.manifest (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3PATCH.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\avatar.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfadel.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfader.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\common-x.css (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\common.css (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbl.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbr.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\include.js (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\index.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\loader.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\loading.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\logo.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\noflash.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.swf (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\topgrad.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\window.ico (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00024339.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00026D27 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0002DE50 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00030B8A (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0003F926 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\000434B8 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00058F57 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00071143 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\000B050B (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0020256E.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00B5A037 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00DF1E58 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0167ECEE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B726BA.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B7290C.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72A73.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72C0A.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72D52 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\02BFB6B2 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0324651C.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0324672F.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246887.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246A8A.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246BF2.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\034B6230 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\setting2.htm.bak (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\settings.dat.bak (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\regTool\account.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\folderzipper.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\icsharpcode.sharpziplib.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.common.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.processingobjectmodel.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.winforms.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\regTool.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\regtool.exe.config (Rogue.RegTool) -> No action taken.
c:\program files\regTool\skybound.gecko.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\system.data.sqlite.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\unins000.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\unins000.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\elNames.xml (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\regdb.s3db (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\regdbnew.s3db (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\system.data.sqlite.xml (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Email\vzorovyemail.txt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg\38\katalog-stranek.sukvos.com.jpg (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\accessiblemarshal.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\crashreporter.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\crashreporter.ini (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dependentlibs.list (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\freebl3.chk (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\freebl3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\ia2marshal.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\javaxpcom.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\javaxpcomglue.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\js.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\js3250.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\LICENSE (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozcrt19.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozctl.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozctlx.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nspr-config (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nspr4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nss3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssckbi.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssdbm3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssutil3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\platform.ini (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plc4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plds4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\README.txt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\redit.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\smime3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\softokn3.chk (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\softokn3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\sqlite3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\ssl3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\update.locale (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\updater.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpcom.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpcshell.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpidl.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpt_dump.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpt_link.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xul.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xulrunner-stub.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xulrunner.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\classic.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\classic.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\comm.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\comm.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\en-US.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\en-us.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\pippki.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\pippki.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\toolkit.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\toolkit.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\accessibility-msaa.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\accessibility.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\alerts.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\appshell.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\appstartup.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\autocomplete.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\autoconfig.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\caps.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\chardet.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\chrome.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\commandhandler.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\commandlines.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\composer.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\compreg.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\contentprefs.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_html.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_htmldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xmldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xslt.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xtf.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\cookie.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\directory.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\docshell_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_canvas.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_core.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_css.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_events.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_geolocation.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_html.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_json.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_loadsave.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_offline.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_range.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_sidebar.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_storage.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_stylesheets.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_svg.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_threads.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_traversal.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_views.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xbl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xpath.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xul.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\downloads.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\editor.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\embed_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\extensions.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\exthandler.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\exthelper.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\fastfind.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\feedprocessor.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\feeds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\find.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\gfx.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\htmlparser.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\imgicon.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\imglib2.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\inspector.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\intl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jar.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jsconsole-clhandler.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jsdservice.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_printing.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_xul.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_xul_tree.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\locale.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\loginmgr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\lwbrk.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mimetype.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mozbrwsr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mozfind.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_about.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_cache.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_cookie.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_dns.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_file.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_ftp.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_http.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_res.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_socket.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_strconv.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_viewsource.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_wifi.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\networkgeolocationprovider.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsaddonrepository.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsbadcerthandler.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsblocklistservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nscontentdispatchchooser.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nscontentprefservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsdefaultclh.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsdownloadmanagerui.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsextensionmanager.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nshandlerservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nshelperappdlg.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nslivemarkservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nslogininfo.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsloginmanager.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsloginmanagerprompter.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsplacesdbflush.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nspostupdatewin.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsprogressdialog.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsproxyautoconfig.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nssearchservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nssearchsuggestions.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nstaggingservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nstrytoclose.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsupdateservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsurlformatter.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nswebhandlerapp.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsxulappinstall.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\oji.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\parentalcontrols.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pipboot.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pipnss.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pippki.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\places.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\plugin.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pluginglue.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pref.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\prefetch.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\profile.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\proxyobject.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\rdf.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\satchel.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\saxparser.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\shistory.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\spellchecker.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage-legacy.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage-mozstorage.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\toolkitprofile.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\toolkitsearch.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txexsltregexfunctions.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txmgr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txtsvc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\uconv.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\unicharutil.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\update.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\uriloader.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\urlformatter.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webbrowserpersist.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webbrowser_core.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webshell_idls.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\widget.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\windowds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\windowwatcher.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_components.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_ds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_io.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_system.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_thread.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_xpti.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpconnect.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpinstall.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpti.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xulapp.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xulapp_setup.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xuldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xultmpl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\zipwriter.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig\platform.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig\prefcalls.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\pref\xulrunner.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\localstore.rdf (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome\userchrome-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome\usercontent-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\localstore.rdf (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome\userchrome-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome\usercontent-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries\en-US.aff (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries\en-US.dic (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\all.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\security-prefs.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\xpinstall.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\debug.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\downloadlastdir.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\downloadutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\iso8601dateutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\microformats.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\placesdbutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\pluralform.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\spatialnavigation.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\utils.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\windowdraggingutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\xpcomutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plugins\npnul32.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\arrow.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\arrowd.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\broken-image.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\charsetalias.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\charsetdata.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\contenteditable.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\designmode.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\editoroverride.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\forms.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\grabber.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\hiddenwindow.html (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\langgroups.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\language.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\loading-image.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\mathml.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\quirk.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\svg.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\ua.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\viewsource.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\wincharset.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd\mathml.dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd\xhtml11.dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40latin1.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40special.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40symbols.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\htmlentityversions.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\mathml20.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\transliterate.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfont.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstandardsymbolsl.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixnonunicode.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixsize1.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontsymbol.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontunicode.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html\folder.png (Rogue.RegTool) -> No action taken.
c:\program files\ThunMail\testabd.dll.vir (Trojan.Agent) -> No action taken.
c:\program files\ThunMail\testabd.exe.vir (Trojan.Agent) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\aplikace regtool na internetu.url (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\odinstalovat aplikaci regtool.lnk (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\regTool.lnk (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\about relevantknowledge.lnk (Spyware.MarketScore) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\privacy policy and user license agreement.lnk (Spyware.MarketScore) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\Support.lnk (Spyware.MarketScore) -> No action taken.

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#5 Příspěvek od cernohous13 »

:o pěkná sbírka - s tím ti musel někdo pomáhat :D
pokud jsi program ještě nezavřel, tak:
Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené

vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych taky rád viděl :)
(jestli už je zavřený, tak MBAM spustit znovu - dát Kompletní kontrola...)
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#6 Příspěvek od Guardian23 »

3 roky jsem na to prakticky nesáhl (léčba apod.). Spoléhal jsem na antivir :) A zatím mi nikdo neukradl peníze z internetového bankovnictví, tak jsem si říkal, že je asi všechno O.K. :D

Tady je log. Jinak to hlásilo, že některé ponožky nemohly být odstraněny :) A pak mám ještě restartovat...zatím s restartem počkám :)

***1/2***
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 5214

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

30.11.2010 13:43:56
mbam-log-2010-11-30 (13-43-56).txt

Typ kontroly: Rychlý test
Testované objekty: 252986
Uplynulý čas: 2 hodin, 16 minut, 20 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 3
Infikované klíče v registru: 128
Infikované hodnoty v registru: 14
Infikované datové položky v registru: 2
Infikované složky: 48
Infikované soubory: 464

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch)

-> Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) ->

Not selected for removal.

Infikované klíče v registru:
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWe

bSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted

successfully.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC2

01FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for

removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6

FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0139

8B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2556

0540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF0

5104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seneka (Trojan.Agent)

-> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Malware.Trace) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.Out

lookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.Outloo

kAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08

d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{67FA02C4-AB30-4e77-A640-78EE8EC8673B}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E3E

F3BD5-02F3-4F99-9DAC-A20637DF084D}_is1 (Rogue.RegTool) -> Quarantined and

deleted successfully.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web

Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web

Search Bar Search Scope Monitor -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearc

h Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch

Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearc

h Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Plugin -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D}

(Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value:

f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet

Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) ->

Value: FunWebProducts -> Quarantined and deleted successfully.

Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath

(Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k

netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on

reboot.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath

(Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k

netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on

reboot.

Infikované složky:
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Delete on

reboot.
c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\setups (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\regTool (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\Data (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\Email (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\imgReg (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\imgReg\38 (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner\chrome (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\components (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\pref (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\chrome (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\modules (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\plugins (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner\res\dtd (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res\html (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\ThunMail (Trojan.Agent) -> Quarantined and deleted

successfully.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge (Spyware.MarketScore) -> Quarantined and

deleted successfully.

Infikované soubory:
c:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch)

-> Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) ->

Not selected for removal.
c:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\dealio toolbar\IE\4.0.2\dealiotoolbarie.dll

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\Plocha\regTool.lnk

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\tj.vbs (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\WINDOWS\system32\drivers\senekajwfoexno.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\senekangvdknxf.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\senekarmdcxeyp.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\ftp_non_crp.exe (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\WINDOWS\system32\service-466.exe (Trojan.Downloader) -> Quarantined and

deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator\avatar.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator\zbucks.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\webfettibtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\m3ntstbr.manifest

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3PATCH.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\avatar.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfadel.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfader.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\common-x.css

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\common.css

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbl.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbr.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\include.js

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\index.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\loader.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\loading.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\logo.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\noflash.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.swf

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\topgrad.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\window.ico

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00024339.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00026D27 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0002DE50 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00030B8A (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0003F926 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\000434B8 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00058F57 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00071143 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\000B050B (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0020256E.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00B5A037 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00DF1E58 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0167ECEE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B726BA.bin (Adware.MyWebSearch) ->


Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#7 Příspěvek od Guardian23 »

***2/2***
Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B7290C.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72A73.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72C0A.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72D52 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\02BFB6B2 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0324651C.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0324672F.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246887.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246A8A.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246BF2.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\034B6230 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\setting2.htm.bak

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\settings.dat.bak

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\regTool\account.dll (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\folderzipper.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\icsharpcode.sharpziplib.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.common.dll (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.processingobjectmodel.dll

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.winforms.dll

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\regTool.exe (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\regtool.exe.config (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\skybound.gecko.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\system.data.sqlite.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\unins000.dat (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\unins000.exe (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\Data\elNames.xml (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\Data\regdb.s3db (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\Data\regdbnew.s3db (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\Data\system.data.sqlite.xml (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\Email\vzorovyemail.txt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\imgReg\38\katalog-stranek.sukvos.com.jpg

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\accessiblemarshal.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\crashreporter.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\crashreporter.ini (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dependentlibs.list (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\freebl3.chk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\freebl3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\ia2marshal.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\javaxpcom.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\javaxpcomglue.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\js.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\js3250.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\LICENSE (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\mozcrt19.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\mozctl.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\mozctlx.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nspr-config (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nspr4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\nss3.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\nssckbi.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nssdbm3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nssutil3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\platform.ini (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\plc4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\plds4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\README.txt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\redit.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\smime3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\softokn3.chk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\softokn3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\sqlite3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\ssl3.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\update.locale (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\updater.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpcom.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xpcshell.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpidl.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xpt_dump.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpt_link.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xul.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xulrunner-stub.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xulrunner.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\classic.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\classic.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\comm.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\comm.manifest (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\en-US.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\en-us.manifest (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\pippki.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\pippki.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\toolkit.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\toolkit.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\accessibility-msaa.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\accessibility.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\alerts.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\appshell.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\appstartup.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\autocomplete.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\autoconfig.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\caps.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\chardet.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\chrome.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\commandhandler.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\commandlines.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\composer.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\compreg.dat (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\contentprefs.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_html.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_htmldoc.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xmldoc.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xslt.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xtf.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\cookie.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\directory.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\docshell_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_base.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_canvas.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_core.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_css.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_events.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_geolocation.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_html.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_json.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_loadsave.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_offline.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_range.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_sidebar.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_storage.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_stylesheets.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_svg.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_threads.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_traversal.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_views.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xbl.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xpath.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xul.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\downloads.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\editor.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\embed_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\extensions.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\exthandler.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\exthelper.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\fastfind.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\feedprocessor.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\feeds.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\find.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\gfx.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\htmlparser.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\imgicon.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\imglib2.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\inspector.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\intl.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jar.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jsconsole-clhandler.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jsdservice.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_printing.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_xul.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_xul_tree.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\locale.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\loginmgr.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\lwbrk.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mimetype.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mozbrwsr.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mozfind.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_about.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_cache.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_cookie.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_dns.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_file.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_ftp.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_http.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_res.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_socket.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_strconv.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_viewsource.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_wifi.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\networkgeolocationprovider.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsaddonrepository.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsbadcerthandler.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsblocklistservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nscontentdispatchchooser.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nscontentprefservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsdefaultclh.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsdownloadmanagerui.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsextensionmanager.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nshandlerservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nshelperappdlg.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nslivemarkservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nslogininfo.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsloginmanager.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsloginmanagerprompter.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsplacesdbflush.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nspostupdatewin.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsprogressdialog.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsproxyautoconfig.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nssearchservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nssearchsuggestions.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nstaggingservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nstrytoclose.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsupdateservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsurlformatter.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nswebhandlerapp.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsxulappinstall.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\oji.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\parentalcontrols.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pipboot.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pipnss.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pippki.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\places.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\plugin.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pluginglue.js (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pref.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\prefetch.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\profile.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\proxyobject.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\rdf.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\satchel.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\saxparser.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\shistory.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\spellchecker.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage-legacy.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage-mozstorage.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\toolkitprofile.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\toolkitsearch.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txexsltregexfunctions.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txmgr.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txtsvc.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\uconv.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\unicharutil.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\update.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\uriloader.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\urlformatter.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webbrowserpersist.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webbrowser_core.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webshell_idls.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\widget.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\windowds.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\windowwatcher.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_components.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_ds.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_io.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_system.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_thread.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_xpti.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpconnect.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpinstall.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpti.dat (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xulapp.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xulapp_setup.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xuldoc.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xultmpl.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\zipwriter.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig\platform.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig\prefcalls.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\pref\xulrunner.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\localstore.rdf

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\chrome\userchrome-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\chrome\usercontent-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US\localstore.rdf

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\US\chrome\userchrome-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\US\chrome\usercontent-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries\en-US.aff (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries\en-US.dic (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\all.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\security-prefs.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\xpinstall.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\debug.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\downloadlastdir.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\downloadutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\iso8601dateutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\microformats.js (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\placesdbutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\pluralform.jsm (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\spatialnavigation.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\utils.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\windowdraggingutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\xpcomutils.jsm (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\plugins\npnul32.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\arrow.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\arrowd.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\broken-image.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\charsetalias.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\charsetdata.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\contenteditable.css (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\designmode.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\editoroverride.css (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\forms.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\grabber.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\hiddenwindow.html (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\html.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\langgroups.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\language.properties (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\loading-image.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\mathml.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\quirk.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\svg.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row.gif (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\ua.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\viewsource.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\wincharset.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\dtd\mathml.dtd (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\dtd\xhtml11.dtd (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables\html40latin1.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\html40special.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\html40symbols.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\htmlentityversions.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables\mathml20.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\transliterate.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfont.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\fonts\mathfontstandardsymbolsl.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\fonts\mathfontstixnonunicode.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixsize1.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontsymbol.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontunicode.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\html\folder.png (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\ThunMail\testabd.dll.vir (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\program files\ThunMail\testabd.exe.vir (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\aplikace regtool na internetu.url (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\odinstalovat aplikaci regtool.lnk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\regTool.lnk (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\about relevantknowledge.lnk

(Spyware.MarketScore) -> Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\privacy policy and user license

agreement.lnk (Spyware.MarketScore) -> Quarantined and deleted

successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\Support.lnk (Spyware.MarketScore) ->

Quarantined and deleted successfully.

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#8 Příspěvek od cernohous13 »

:arrow: Restart potřebuje na vyčištění paměti.

:arrow: pokračujeme
Stáhni si Obrázek ComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#9 Příspěvek od Guardian23 »

Po skončění úlohy se objevila modrá obrazovka smrti, tak jsem se lekl. Ale po resetu systém naběhl. Snad to při dalším restartu/vypnutí taky dobře naběhne.

LOG
ComboFix 10-11-29.05 - Administrator 30.11.2010 16:02:07.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1263 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator.LENKA\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira FireWall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio
c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio\res\widgets.xml
c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
c:\documents and settings\Administrator.LENKA\Plocha\Jsou rozdíly v nakupování ve městě a na vesnici.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vrátit starou zářivku je umění.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vytápění dřevem prudce zdražuje.doc
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\components\config.ini
c:\program files\Dealio Toolbar\FF\components\dealioToolbarFF.dll
c:\program files\Dealio Toolbar\FF\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\components\IFBHOWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\login.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\parser.js
c:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\separator.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\4.0.2\config.ini
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\install.rdf
c:\program files\Search Settings
c:\program files\Search Settings\FF\components\IFBHOSearch.xpt
c:\program files\Search Settings\FF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Search Settings\FF\components\IFHelperPreferences.xpt
c:\program files\Search Settings\FF\components\SearchSettingsFF.dll
c:\program files\Search Settings\FF\chrome.manifest
c:\program files\Search Settings\FF\chrome\content\plugin.js
c:\program files\Search Settings\FF\chrome\content\plugin.xul
c:\program files\Search Settings\FF\chrome\content\protection.js
c:\program files\Search Settings\FF\chrome\content\utils.js
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Search Settings\FF\install.rdf
c:\program files\Search Settings\SearchSettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\program files\Search Settings\SearchSettingsRes409.VIR
c:\windows\system32\senekaiwqvvrcv.dat
c:\windows\system32\senekamdwxtiqj.dat
c:\windows\system32\senekatqxlxyef.dat
c:\windows\system32\senekauplvbuwm.dat
c:\windows\system32\senekawhkypbiv.dat

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-28 do 2010-11-30 )))))))))))))))))))))))))))))))
.

2010-11-30 15:01 . 2010-11-30 15:01 -------- d-----w- C:\32788R22FWJFW
2010-11-30 13:22 . 2010-11-30 13:44 -------- d-----w- c:\program files\HDD Regenerator
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 09:14 . 2010-11-30 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-29 20:28 . 2010-11-30 08:00 -------- d-----w- c:\program files\trend micro
2010-11-29 20:28 . 2010-11-29 20:28 -------- d-----w- C:\rsit
2010-11-29 18:27 . 2007-06-29 13:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2010-11-29 18:27 . 2010-11-29 18:27 -------- d-----w- c:\program files\AMD
2010-11-29 17:42 . 2010-11-29 17:42 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-11-29 17:42 . 2010-11-29 17:42 -------- d-----w- c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\eSupport.com
2010-11-23 14:29 . 2010-11-23 14:29 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-05 14:43 . 2010-11-05 23:17 -------- d-----w- c:\program files\CamStudio

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-24 08:09 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-24 08:09 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-08-04 11:31 . 2009-02-05 17:39 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-02-08 133104]
"QIP2005"="c:\program files\QIP\qip.exe" [2008-12-09 3259392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-04 30192]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-17 148888]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-03-12 119152]
"LiveZilla"="c:\program files\LiveZilla\LiveZilla.exe" [2010-05-17 2651576]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-10-24 202256]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files (x86)\OpenOffice.org 2.4\program\quickstart.exe [2008-5-30 393216]

c:\documents and settings\Administrator.LENKA\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]

c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-11 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-5-28 606208]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-12 813584]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\bwin\\StartbwinPoker.exe"=
"d:\\hl22\\HALF LIFE 2\\hl2.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\CrosuS\\CrosuSApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [26.9.2009 14:27 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [26.9.2009 14:27 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.2.2009 0:38 717296]
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [28.4.2010 20:05 102856]
R2 AntiVirFirewallService;Avira FireWall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [28.4.2010 20:05 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [28.4.2010 20:05 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [26.8.2009 21:51 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [28.4.2010 20:05 405672]
R2 Apache2.2;Apache2.2;d:\nydecky.cz\xampp\apache\bin\httpd.exe [17.2.2010 15:44 29416]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16.12.2009 17:38 375296]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [26.9.2010 13:32 20328]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 10:16 1107336]
R2 KoopPdfService;KoopPdfService;c:\program files\Kooperativa\Services\KoopPDFServer.exe [4.7.2010 10:38 447488]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [6.11.2008 19:00 1171456]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [28.4.2010 20:05 79432]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [29.11.2010 18:42 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5.2.2009 18:39 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [13.4.2010 14:20 30576]
S4 Swentuip;Swentuip; [x]
.
Obsah adresáře 'Naplánované úlohy'

2009-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-05-02 c:\windows\Tasks\Install.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2010-04-28 19:48]

2010-07-03 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-03-12 16:41]

2010-04-13 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2010-03-12 16:41]

2010-11-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-11-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-01-20 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 16:29]
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.cz
FF - component: c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\documents and settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Ranky: ranky@ranky.cz - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\ranky@ranky.cz
FF - Extension: PimpZilla: {a02c0c70-605c-11da-8cd6-0800200c9a66} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Counterpixel: counterpixel@jabubo.de - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\counterpixel@jabubo.de
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: Cooliris: piclens@cooliris.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com
FF - Extension: SEOProfesional: seo@profesional - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\seo@profesional
FF - Extension: 20-20 3D Viewer: 2020Player@2020Technologies.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\2020Player@2020Technologies.com
FF - Extension: Collabim: {db0832f2-613f-4afb-8b6a-155fe76eb32e} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{db0832f2-613f-4afb-8b6a-155fe76eb32e}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-netmon.exe - c:\program files\netmon\netmon.exe
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-Escape Whisper Valley - e:\hry\popgames\Escape Whisper Valley\PopUninstall.exe
AddRemove-Hledik - Poradce - makléř FAC - c:\gen_makler\\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-30 16:14
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-484763869-1482476501-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CAF28C9-EB0A-7D46-95A8-6DBEC787F657}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG06.00.00.01WORKSTATION"="3523683F98B7D088E5D186AA3446897566BA45D8E7FA61F05616BE33CFF972057601695E63AA1FBE0FE17D8FF920D84996CD24ECA790BE9C3C908301E2D406AFB4B30CBEF9883E4B5723A41163A8585E93D416FD50CE03EA2F0DD7DB16755703552BA012E8CE5950FA0748E7602C40AC8DE184EF55F49250FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555A2D97226D213B555A9C6AECB7A5D1407F9EF2B1EA2605560695DE24B9A023BAD660FDA1F3393A48652442AE2F83DB5ACDF9C50E8E6AB9037BD08EFF3BD097145204552A52D8398B789EFB5844BE30974EE1E7C0B5F3113C9268F95C978EB33D42AEC4C20D5D13D7A261654F5A0325875DA7D34957459CA6DCB1EF40A36831DA541EFA8923E65F9B39A8041A45041F7CA69093180E28C1C97E722E1D2B9293DA936FE79E44E2BAC6D6BC1EAE085ACB239F450DE26BAB7DCE34B4CE728193B1AF26C8C8463BF11A6D3B0AB74DF401647246BA9DDC2E1CE5811589443F0BC9D2A3BDBCFC43FA28C2B381AD8363D5522E69750AC837B11444E8185B4E678E4355A5D12C2690DD815F58E68A33C736BF837C03838D754D4146FBCE02A76EEA0ED8A592F2654C59925B1F06F2C44667EC652F04E6C17B90D3CE66D0738CDE657B68D52E6FC9CC36F3C019B99D7445A5F3EC71DD02FB279703D4B62AC6377D7C281AD91800E0B4839DEF76FE34E6178B09118E192A94E45851CAE8E9877389E6FC324035A64A1F72A951F72607B79CDE97BBA7BF7484233AA64928825820378417A24B5E2CF0F5CC76A75CB32101A4D5837984CFCBB1BBE90226E0DC355020AEBA3CE5D20E2BCDFEDED6A4995FE084B1B850FDAAF7B9AC6BA682E78F586145BF9C03ED329F343544BB2645CD5813A81A4ABF0CE323D340C044BAF4FD3F1C9D5C95AFC92AA1FF16CE2D13A1854145C0DBE7205F73B0211361764C5B788B2E7CA0DF80C3A6544CBC20BE6BAB707F54D6F04A5844794888D4FF5D3B8FCD32E69ECC7AC5F102C0585D1ED10A616F6AA220F64961D549BD539467539C28D0807FAD2D6885E79694A0DFB0CF23236C07BA0B32399F15644B3D9EB3EB992FC8C2BFD7965A16504173DFC043635873B1675460BD987182E933067F7CB804C02DCC6083FF5134560464EAA13948342EE3DE64028F1BC99DA251B8E85713B0677084B63E7DEFCC0611CAF9B35A08D75BC8EE4F37E2D9A7505258AAF90511ACA5CB2F00D9AC87F907D51D90B5B2B07A43877C778679E859CF45856DFFDE55399D291AF3762B344E0D3AF0866D8D427C814782A98A2AD657518931DE612FA2266A2F2C6C6AF6E72D12299B75067962A4F2AA8EE54CF1727DA81C0BE4179B24197B6B3B854D4213CF5CC822D1F2239CF9978"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1408)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1472)
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(4872)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msi.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft ActiveSync\Wcescomm.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
d:\nydecky.cz\xampp\mysql\bin\mysqld.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\windows\system32\wscntfy.exe
c:\program files\Firebird\bin\fbserver.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Avira\AntiVir Desktop\usrreq.exe
c:\program files\Avira\AntiVir Desktop\checkt.exe
.
**************************************************************************
.
Celkový čas: 2010-11-30 16:18:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-30 15:18

Před spuštěním: 3 047 518 208
Po spuštění: Volných bajtů: 10 603 380 736

- - End Of File - - 7D72ED2BB228563A27BCF05ED96B05E1

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#10 Příspěvek od cernohous13 »

Jak velký problém jsou vymazané *.doc?
c:\documents and settings\Administrator.LENKA\Plocha\Jsou rozdíly v nakupování ve městě a na vesnici.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vrátit starou zářivku je umění.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vytápění dřevem prudce zdražuje.doc

je nutné je vrátit? na ostatní připravím script
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#11 Příspěvek od Guardian23 »

Těchto souborů jsem se chtěl dávno zbavit, ale nešly mi smazat. Takže díky za odstranění :)

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#12 Příspěvek od cernohous13 »

:arrow: Pokud netrváš na vyhledávači od c:\program files\Ask.com - odinstaluj (nemáme ho rádi)

:arrow: Otevři Poznámkový blok (Notepad) a zkopíruj celý zelený text z "CFscriptu".
Soubor ulož na plochu jako CFscript.txt a jeho ikonu přetáhni myší nad ikonu ComboFixu - tam pusť.
Obrázek
ComboFix se spustí - počkej na log a vlož ho sem.
CFscript

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"NeroFilterCheck"=-
"SunJavaUpdateSched"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"QuickTime Task"=-
"TkBellExe"=-

Driver::
Firebird Guardian
Firebird Server
Swentuip

File::
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\Install.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

RegNull::
[HKEY_USERS\S-1-5-21-484763869-1482476501-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CAF28C9-EB0A-7D46-95A8-6DBEC787F657}*]
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#13 Příspěvek od Guardian23 »

Provedeno.

Je to všechno? :)

Pokud ano, tak moc děkuji.

Kdyžtak ještě zasílám log.
ComboFix 10-11-29.05 - Administrator 30.11.2010 19:20:46.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1235 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator.LENKA\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator.LENKA\Plocha\CFscript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira FireWall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}

FILE ::
"c:\windows\Tasks\AppleSoftwareUpdate.job"
"c:\windows\Tasks\Install.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\Install.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_Swentuip


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-28 do 2010-11-30 )))))))))))))))))))))))))))))))
.

2010-11-30 13:22 . 2010-11-30 13:44 -------- d-----w- c:\program files\HDD Regenerator
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 09:14 . 2010-11-30 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-29 20:28 . 2010-11-30 08:00 -------- d-----w- c:\program files\trend micro
2010-11-29 20:28 . 2010-11-29 20:28 -------- d-----w- C:\rsit
2010-11-29 18:27 . 2007-06-29 13:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2010-11-29 18:27 . 2010-11-29 18:27 -------- d-----w- c:\program files\AMD
2010-11-29 17:42 . 2010-11-29 17:42 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-11-29 17:42 . 2010-11-29 17:42 -------- d-----w- c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\eSupport.com
2010-11-23 14:29 . 2010-11-23 14:29 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-05 14:43 . 2010-11-05 23:17 -------- d-----w- c:\program files\CamStudio

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-24 08:09 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-24 08:09 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-08-04 11:31 . 2009-02-05 17:39 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"="c:\program files\QIP\qip.exe" [2008-12-09 3259392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-04 30192]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-03-12 119152]
"LiveZilla"="c:\program files\LiveZilla\LiveZilla.exe" [2010-05-17 2651576]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files (x86)\OpenOffice.org 2.4\program\quickstart.exe [2008-5-30 393216]

c:\documents and settings\Administrator.LENKA\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]

c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-11 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-5-28 606208]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-12 813584]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\bwin\\StartbwinPoker.exe"=
"d:\\hl22\\HALF LIFE 2\\hl2.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\CrosuS\\CrosuSApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [26.9.2009 14:27 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [26.9.2009 14:27 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.2.2009 0:38 717296]
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [28.4.2010 20:05 102856]
R2 AntiVirFirewallService;Avira FireWall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [28.4.2010 20:05 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [28.4.2010 20:05 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [26.8.2009 21:51 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [28.4.2010 20:05 405672]
R2 Apache2.2;Apache2.2;d:\nydecky.cz\xampp\apache\bin\httpd.exe [17.2.2010 15:44 29416]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16.12.2009 17:38 375296]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [26.9.2010 13:32 20328]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 10:16 1107336]
R2 KoopPdfService;KoopPdfService;c:\program files\Kooperativa\Services\KoopPDFServer.exe [4.7.2010 10:38 447488]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [6.11.2008 19:00 1171456]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [28.4.2010 20:05 79432]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [29.11.2010 18:42 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5.2.2009 18:39 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [13.4.2010 14:20 30576]
.
Obsah adresáře 'Naplánované úlohy'

2010-07-03 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-03-12 16:41]

2010-04-13 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2010-03-12 16:41]
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.cz
FF - component: c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\documents and settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Ranky: ranky@ranky.cz - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\ranky@ranky.cz
FF - Extension: PimpZilla: {a02c0c70-605c-11da-8cd6-0800200c9a66} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Counterpixel: counterpixel@jabubo.de - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\counterpixel@jabubo.de
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: Cooliris: piclens@cooliris.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com
FF - Extension: SEOProfesional: seo@profesional - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\seo@profesional
FF - Extension: 20-20 3D Viewer: 2020Player@2020Technologies.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\2020Player@2020Technologies.com
FF - Extension: Collabim: {db0832f2-613f-4afb-8b6a-155fe76eb32e} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{db0832f2-613f-4afb-8b6a-155fe76eb32e}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-30 19:29
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG06.00.00.01WORKSTATION"="3523683F98B7D088E5D186AA3446897566BA45D8E7FA61F05616BE33CFF972057601695E63AA1FBE0FE17D8FF920D84996CD24ECA790BE9C3C908301E2D406AFB4B30CBEF9883E4B5723A41163A8585E93D416FD50CE03EA2F0DD7DB16755703552BA012E8CE5950FA0748E7602C40AC8DE184EF55F49250FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555A2D97226D213B555A9C6AECB7A5D1407F9EF2B1EA2605560695DE24B9A023BAD660FDA1F3393A48652442AE2F83DB5ACDF9C50E8E6AB9037BD08EFF3BD097145204552A52D8398B789EFB5844BE30974EE1E7C0B5F3113C9268F95C978EB33D42AEC4C20D5D13D7A261654F5A0325875DA7D34957459CA6DCB1EF40A36831DA541EFA8923E65F9B39A8041A45041F7CA69093180E28C1C97E722E1D2B9293DA936FE79E44E2BAC6D6BC1EAE085ACB239F450DE26BAB7DCE34B4CE728193B1AF26C8C8463BF11A6D3B0AB74DF401647246BA9DDC2E1CE5811589443F0BC9D2A3BDBCFC43FA28C2B381AD8363D5522E69750AC837B11444E8185B4E678E4355A5D12C2690DD815F58E68A33C736BF837C03838D754D4146FBCE02A76EEA0ED8A592F2654C59925B1F06F2C44667EC652F04E6C17B90D3CE66D0738CDE657B68D52E6FC9CC36F3C019B99D7445A5F3EC71DD02FB279703D4B62AC6377D7C281AD91800E0B4839DEF76FE34E6178B09118E192A94E45851CAE8E9877389E6FC324035A64A1F72A951F72607B79CDE97BBA7BF7484233AA64928825820378417A24B5E2CF0F5CC76A75CB32101A4D5837984CFCBB1BBE90226E0DC355020AEBA3CE5D20E2BCDFEDED6A4995FE084B1B850FDAAF7B9AC6BA682E78F586145BF9C03ED329F343544BB2645CD5813A81A4ABF0CE323D340C044BAF4FD3F1C9D5C95AFC92AA1FF16CE2D13A1854145C0DBE7205F73B0211361764C5B788B2E7CA0DF80C3A6544CBC20BE6BAB707F54D6F04A5844794888D4FF5D3B8FCD32E69ECC7AC5F102C0585D1ED10A616F6AA220F64961D549BD539467539C28D0807FAD2D6885E79694A0DFB0CF23236C07BA0B32399F15644B3D9EB3EB992FC8C2BFD7965A16504173DFC043635873B1675460BD987182E933067F7CB804C02DCC6083FF5134560464EAA13948342EE3DE64028F1BC99DA251B8E85713B0677084B63E7DEFCC0611CAF9B35A08D75BC8EE4F37E2D9A7505258AAF90511ACA5CB2F00D9AC87F907D51D90B5B2B07A43877C778679E859CF45856DFFDE55399D291AF3762B344E0D3AF0866D8D427C814782A98A2AD657518931DE612FA2266A2F2C6C6AF6E72D12299B75067962A4F2AA8EE54CF1727DA81C0BE4179B24197B6B3B854D4213CF5CC822D1F2239CF9978"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1404)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1460)
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(4568)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
d:\nydecky.cz\xampp\mysql\bin\mysqld.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\windows\RTHDCPL.EXE
c:\program files\Firebird\bin\fbserver.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft ActiveSync\Wcescomm.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Avira\AntiVir Desktop\checkt.exe
.
**************************************************************************
.
Celkový čas: 2010-11-30 19:35:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-30 18:35
ComboFix2.txt 2010-11-30 15:18

Před spuštěním: Volných bajtů: 10 554 580 992
Po spuštění: Volných bajtů: 10 594 828 288

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 2A2E91BC1B0B73B8FD233BA3FF753A45

Avatar uživatele
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8720
Registrován: 09 Pro 2006 06:19
Místo/Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#14 Příspěvek od cernohous13 »

:arrow: ComboFix odinstalujeme
jdi Start -> Spustit... a zkopíruj ComboFix /Uninstall (pozor, za x je mezera) -> OK

:arrow: Stáhni TempFolderCleaner http://oldtimer.geekstogo.com/TFC.exe
Zavři všechny programy a spusť. Po ukončení akce bude PC restartován.
Pokud ne, restartuj sám.
(čistí Temp složky , nečistí URL, historii, prefetch ani cookies)

:arrow: stáhni program OTC tady: http://oldtimer.geekstogo.com/OTC.exe - spusť ho -> "CleanUp" (smaže dříve použité čističe)

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace

:arrow: dej mi nový RSIT + popis chování PC (nějaké problémy?)
doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština

:arrow: Nakonec mi dej současný RSIT log
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 Lis 2010 09:20

Re: Kontrola logu

#15 Příspěvek od Guardian23 »

Tady je log. Defragmentaci udělám později. Jinak rychlost načítání, zdá se, se o něco snížila. Každopádně budu muset z plochy smazat tu hromadu souborů, zřejmě to má na náběh PC taky vliv.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-11-30 20:41:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 11 GB (23%) free of 50 GB
Total RAM: 2047 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:42:02, on 30.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\LiveZilla\LiveZilla.exe
D:\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Firebird\bin\fbserver.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator.LENKA\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [LiveZilla] "C:\Program Files\LiveZilla\LiveZilla.exe" -minimize
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/63.27/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0379200234
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - D:\nydecky.cz\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KoopPdfService - Unknown owner - C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: MySQL - MySQL AB - D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.LEN/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 12215 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IcePick_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_LifeExp_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-10-24 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"GBB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe [2006-07-12 356352]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-03-16 47392]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-03-12 119152]
"LiveZilla"=C:\Program Files\LiveZilla\LiveZilla.exe [2010-05-17 2651576]
"iTunesHelper"=D:\iTunes\iTunesHelper.exe [2010-07-21 141608]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Administrator.LENKA\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2009-07-20 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\bwin\StartbwinPoker.exe"="C:\Program Files\bwin\StartbwinPoker.exe:*:Enabled:StartbwinPoker.exe"
"D:\hl22\HALF LIFE 2\hl2.exe"="D:\hl22\HALF LIFE 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Autodesk\backburner\monitor.exe"="C:\Program Files\Autodesk\backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\backburner\manager.exe"="C:\Program Files\Autodesk\backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\backburner\server.exe"="C:\Program Files\Autodesk\backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Teamspeak2_RC2\server_windows.exe"="C:\Program Files\Teamspeak2_RC2\server_windows.exe:*:Enabled:Server"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\CrosuS\CrosuSApp.exe"="C:\Program Files\CrosuS\CrosuSApp.exe:*:Enabled:Crosus"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\iTunes\iTunes.exe"="D:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.js - edit -
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-11-30 20:41:57 ----D---- C:\rsit
2010-11-30 20:26:53 ----D---- C:\Program Files\CCleaner
2010-11-30 20:13:45 ----SHD---- C:\RECYCLER
2010-11-30 19:25:49 ----D---- C:\WINDOWS\temp
2010-11-30 18:55:25 ----RASHD---- C:\cmdcons
2010-11-30 15:31:51 ----D---- C:\WINDOWS\ERDNT
2010-11-30 14:22:38 ----D---- C:\Program Files\HDD Regenerator
2010-11-30 10:14:52 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 10:14:43 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-11-30 10:14:41 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-11-30 10:14:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 10:14:41 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-11-29 21:28:16 ----D---- C:\Program Files\trend micro
2010-11-29 19:27:21 ----A---- C:\WINDOWS\system32\drivers\AmdLLD.sys
2010-11-29 19:27:19 ----D---- C:\Program Files\AMD
2010-11-29 18:42:50 ----A---- C:\WINDOWS\system32\drivers\DrvAgent32.sys
2010-11-23 15:29:25 ----D---- C:\Program Files\Microsoft Silverlight
2010-11-05 15:43:18 ----D---- C:\Program Files\CamStudio
2010-10-31 14:48:19 ----A---- C:\WINDOWS\oodcnt.INI
2010-10-31 11:56:42 ----D---- C:\WINDOWS\system32\oodag
2010-10-31 10:00:37 ----D---- C:\Program Files\OO Software

======List of files/folders modified in the last 1 months======

2010-11-30 20:28:38 ----D---- C:\WINDOWS\Minidump
2010-11-30 20:28:38 ----D---- C:\WINDOWS\Debug
2010-11-30 20:28:38 ----D---- C:\WINDOWS
2010-11-30 20:26:53 ----D---- C:\Program Files
2010-11-30 20:25:03 ----SHD---- C:\WINDOWS\Installer
2010-11-30 20:24:28 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-30 20:15:52 ----SHD---- C:\System Volume Information
2010-11-30 20:15:52 ----D---- C:\WINDOWS\system32\Restore
2010-11-30 20:13:44 ----D---- C:\WINDOWS\system32
2010-11-30 19:35:14 ----D---- C:\WINDOWS\system32\drivers
2010-11-30 19:28:49 ----A---- C:\WINDOWS\system.ini
2010-11-30 19:28:19 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-30 19:26:11 ----D---- C:\WINDOWS\system32\config
2010-11-30 19:25:35 ----SD---- C:\WINDOWS\Tasks
2010-11-30 19:24:26 ----D---- C:\WINDOWS\AppPatch
2010-11-30 19:24:24 ----D---- C:\Program Files\Common Files
2010-11-30 18:55:29 ----RASH---- C:\boot.ini
2010-11-30 17:35:39 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2010-11-30 14:55:28 ----HD---- C:\WINDOWS\inf
2010-11-30 14:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2010-11-30 12:29:25 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-11-29 20:54:53 ----A---- C:\WINDOWS\wincmd.ini
2010-11-29 19:27:27 ----A---- C:\Boot.bak
2010-11-26 13:45:45 ----D---- C:\Program Files\Simulace_2009
2010-11-25 18:48:33 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-11-23 15:29:34 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-11-22 15:36:13 ----D---- C:\Program Files\Mozilla Firefox
2010-11-22 15:36:02 ----A---- C:\WINDOWS\BRWMARK.INI
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Adobe
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Adobe
2010-11-19 15:15:07 ----D---- C:\Program Files\bwin
2010-11-18 17:17:27 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real
2010-11-18 17:17:20 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Real
2010-11-14 21:13:48 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Simulace_2009
2010-11-05 15:51:23 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-03 19:06:16 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-03 17:06:54 ----RSD---- C:\WINDOWS\assembly
2010-11-03 17:05:04 ----D---- C:\Program Files\AEGON Expert 2.0
2010-11-01 11:53:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CPC
2010-11-01 11:49:37 ----D---- C:\DATA_CPC
2010-10-31 23:48:20 ----D---- C:\Program Files\CPC
2010-10-31 10:02:17 ----D---- C:\WINDOWS\Help
2010-10-31 09:43:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-07-20 41728]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-11-20 43872]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-02-01 717296]
R1 avfwot;avfwot; C:\WINDOWS\system32\DRIVERS\avfwot.sys [2010-04-28 102856]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-04-28 124784]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-04-28 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-04-28 60936]
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 cpuz134;cpuz134; \??\C:\WINDOWS\system32\drivers\cpuz134_x32.sys []
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-18 88448]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-18 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-18 55936]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\WINDOWS\system32\DRIVERS\AVerBDA3x.sys [2006-12-14 1171456]
R3 avfwim;AvFw Packet Filter Miniport; C:\WINDOWS\system32\DRIVERS\avfwim.sys [2010-04-28 79432]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-22 17480]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-18 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-12 248192]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2010-03-12 30576]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023k.sys [2002-08-12 11136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirFirewallService;Avira FireWall; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [2010-04-28 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2010-04-28 337064]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-28 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-04-28 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-04-28 405672]
R2 Apache2.2;Apache2.2; D:\nydecky.cz\xampp\apache\bin\httpd.exe [2009-12-20 29416]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-23 77944]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-01-15 32256]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R2 KoopPdfService;KoopPdfService; C:\Program Files\Kooperativa\Services\KoopPDFServer.exe [2010-07-04 447488]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-03-12 139632]
R2 MySQL;MySQL; D:\nydecky.cz\xampp\mysql\bin\mysqld.exe [2009-12-20 6095504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2004-05-17 184320]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-11 68096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-22 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Odpovědět