C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Dobrý den. Mám problém s virem trojský kůň. Jako antivir používám Eset smart security. Při spuštění windowsů (Vista) mi vyskočí tabulka Run dll s textem: chyba při načítání souboru C:/windows/system 32/sshnas.21.dll - uvedený modul nebyl nalezen. Nevíte někdo co s tím aniž bych musel formátovat. Děkuji za odpověď
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Zdravim, pekne odpoledne preji a vitam Vas u nas na foru
Prectete si prosim pravidla fora
Havet to je, ale format nevyzaduje...
Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti, navic pri zatazenem pocasi jake ted v okrese Kromeriz panuje, neni nic videt
Ale dosti legracek, kouknem na to
Kliknete do meho podpisu na RSIT a dejte log z nej - navod Vas povede...
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
mám obavy, že se v tom moc nevyznám co jste mi napsal 
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Abychom mohli urcit kde havet presne je, tak potrebuji log z RSIT - navod je zde http://www.viry.cz/forum/viewtopic.php?f=24&t=81939 - udelejte dle nej sken a log mi sem pak vlozte...
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Po ukonceni skenu se vytvori dva logy - log.txt a info.txt - oba dva my sem vlozte - pripadne budou ulozeny v c:\rsit
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
jeste mi to nedobehlo ten listing co mam delat?
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
jo uz to je
Logfile of random's system information tool 1.08 (written by random/random)
Run by Notebook at 2010-12-14 15:22:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 141 GB (59%) free of 238 GB
Total RAM: 3062 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:28, on 14.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\pdf24\pdf24.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\Downloads\RSIT.exe
C:\Program Files\trend micro\Notebook.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\Notebook\AppData\Local\Temp\Tvt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll/206 (file missing)
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9809 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll [2010-04-13 662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-10 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"PDFPrint"=C:\Program Files\pdf24\pdf24.exe [2010-03-11 208528]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-07-10 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"JP595IR86O"=C:\Users\Notebook\AppData\Local\Temp\Tvt.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-12-14 15:22:27 ----D---- C:\Program Files\trend micro
2010-12-14 15:22:26 ----D---- C:\rsit
2010-12-14 13:12:35 ----D---- C:\Program Files\MSXML 4.0
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-13 18:37:56 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-12-13 18:37:52 ----D---- C:\Program Files\AGEIA Technologies
2010-12-13 18:37:50 ----D---- C:\ProgramData\SolidWorks
2010-12-13 18:37:50 ----D---- C:\Program Files\SolidWorks Corp
2010-12-13 18:36:35 ----D---- C:\SolidWorks Data
2010-12-13 13:12:39 ----D---- C:\Users\Notebook\AppData\Roaming\BitComet
2010-12-13 13:12:39 ----D---- C:\Downloads
2010-12-13 13:11:42 ----D---- C:\Program Files\BitComet
2010-12-11 17:14:14 ----D---- C:\ProgramData\Macrovision
2010-12-10 13:01:21 ----D---- C:\ProgramData\FLEXnet
2010-12-10 12:56:36 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-12-10 12:36:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-12-10 12:36:12 ----D---- C:\Program Files\MSECache
2010-12-10 12:33:46 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2010-12-10 12:23:40 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-10 12:13:24 ----D---- C:\Windows\SolidWorks
2010-12-10 12:13:19 ----D---- C:\Users\Notebook\AppData\Roaming\SolidWorks
2010-11-23 18:56:52 ----D---- C:\Users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 18:56:45 ----D---- C:\ProgramData\progeSOFT
2010-11-23 18:52:59 ----A---- C:\Windows\system32\cdintf251.dll
2010-11-23 18:51:28 ----A---- C:\Windows\system32\drivers\eusk3usb.sys
2010-11-23 18:51:21 ----A---- C:\Windows\system32\vbar332.dll
2010-11-15 19:34:51 ----D---- C:\Program Files\Common Files\3DO Shared
======List of files/folders modified in the last 1 months======
2010-12-14 15:22:30 ----D---- C:\Windows\Temp
2010-12-14 15:22:27 ----RD---- C:\Program Files
2010-12-14 14:55:08 ----D---- C:\Windows\System32
2010-12-14 14:55:07 ----D---- C:\Windows\inf
2010-12-14 14:55:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-14 14:37:06 ----D---- C:\Windows
2010-12-14 13:31:28 ----SHD---- C:\System Volume Information
2010-12-14 13:13:45 ----SHD---- C:\Windows\Installer
2010-12-14 13:13:43 ----D---- C:\Windows\winsxs
2010-12-14 08:16:57 ----D---- C:\Windows\Tasks
2010-12-13 22:32:04 ----D---- C:\Windows\system32\Tasks
2010-12-13 19:10:44 ----D---- C:\Windows\system32\catroot2
2010-12-13 18:57:07 ----D---- C:\Windows\Microsoft.NET
2010-12-13 18:57:02 ----RSD---- C:\Windows\assembly
2010-12-13 18:50:32 ----D---- C:\ProgramData\Microsoft Help
2010-12-13 18:49:27 ----D---- C:\Windows\system32\catroot
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files
2010-12-13 18:40:02 ----RSD---- C:\Windows\Fonts
2010-12-13 18:37:53 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-13 18:37:52 ----D---- C:\Program Files\Microsoft Office
2010-12-13 18:37:50 ----HD---- C:\ProgramData
2010-12-13 17:18:19 ----D---- C:\Windows\Logs
2010-12-13 13:11:06 ----D---- C:\Program Files\Mozilla Firefox
2010-12-13 11:57:11 ----D---- C:\Windows\Prefetch
2010-12-11 17:55:27 ----D---- C:\Windows\system32\WDI
2010-12-10 12:54:06 ----SD---- C:\Users\Notebook\AppData\Roaming\Microsoft
2010-12-10 12:37:49 ----SD---- C:\ProgramData\Microsoft
2010-12-10 12:37:18 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-25 17:41:29 ----D---- C:\Program Files\Internet Explorer
2010-11-25 17:40:39 ----D---- C:\Windows\system32\cs-CZ
2010-11-25 17:36:06 ----D---- C:\Windows\system32\en-US
2010-11-25 17:36:04 ----D---- C:\Program Files\Microsoft.NET
2010-11-23 18:51:28 ----D---- C:\Windows\system32\drivers
2010-11-15 19:36:15 ----D---- C:\Program Files\3DO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-12 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 al06i5e8;al06i5e8; C:\Windows\system32\drivers\al06i5e8.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-13 867080]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-13 79360]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Notebook at 2010-12-14 15:22:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 141 GB (59%) free of 238 GB
Total RAM: 3062 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:28, on 14.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\pdf24\pdf24.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\Downloads\RSIT.exe
C:\Program Files\trend micro\Notebook.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\Notebook\AppData\Local\Temp\Tvt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll/206 (file missing)
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9809 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll [2010-04-13 662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-10 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"PDFPrint"=C:\Program Files\pdf24\pdf24.exe [2010-03-11 208528]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-07-10 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"JP595IR86O"=C:\Users\Notebook\AppData\Local\Temp\Tvt.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-12-14 15:22:27 ----D---- C:\Program Files\trend micro
2010-12-14 15:22:26 ----D---- C:\rsit
2010-12-14 13:12:35 ----D---- C:\Program Files\MSXML 4.0
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-13 18:37:56 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-12-13 18:37:52 ----D---- C:\Program Files\AGEIA Technologies
2010-12-13 18:37:50 ----D---- C:\ProgramData\SolidWorks
2010-12-13 18:37:50 ----D---- C:\Program Files\SolidWorks Corp
2010-12-13 18:36:35 ----D---- C:\SolidWorks Data
2010-12-13 13:12:39 ----D---- C:\Users\Notebook\AppData\Roaming\BitComet
2010-12-13 13:12:39 ----D---- C:\Downloads
2010-12-13 13:11:42 ----D---- C:\Program Files\BitComet
2010-12-11 17:14:14 ----D---- C:\ProgramData\Macrovision
2010-12-10 13:01:21 ----D---- C:\ProgramData\FLEXnet
2010-12-10 12:56:36 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-12-10 12:36:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-12-10 12:36:12 ----D---- C:\Program Files\MSECache
2010-12-10 12:33:46 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2010-12-10 12:23:40 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-10 12:13:24 ----D---- C:\Windows\SolidWorks
2010-12-10 12:13:19 ----D---- C:\Users\Notebook\AppData\Roaming\SolidWorks
2010-11-23 18:56:52 ----D---- C:\Users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 18:56:45 ----D---- C:\ProgramData\progeSOFT
2010-11-23 18:52:59 ----A---- C:\Windows\system32\cdintf251.dll
2010-11-23 18:51:28 ----A---- C:\Windows\system32\drivers\eusk3usb.sys
2010-11-23 18:51:21 ----A---- C:\Windows\system32\vbar332.dll
2010-11-15 19:34:51 ----D---- C:\Program Files\Common Files\3DO Shared
======List of files/folders modified in the last 1 months======
2010-12-14 15:22:30 ----D---- C:\Windows\Temp
2010-12-14 15:22:27 ----RD---- C:\Program Files
2010-12-14 14:55:08 ----D---- C:\Windows\System32
2010-12-14 14:55:07 ----D---- C:\Windows\inf
2010-12-14 14:55:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-14 14:37:06 ----D---- C:\Windows
2010-12-14 13:31:28 ----SHD---- C:\System Volume Information
2010-12-14 13:13:45 ----SHD---- C:\Windows\Installer
2010-12-14 13:13:43 ----D---- C:\Windows\winsxs
2010-12-14 08:16:57 ----D---- C:\Windows\Tasks
2010-12-13 22:32:04 ----D---- C:\Windows\system32\Tasks
2010-12-13 19:10:44 ----D---- C:\Windows\system32\catroot2
2010-12-13 18:57:07 ----D---- C:\Windows\Microsoft.NET
2010-12-13 18:57:02 ----RSD---- C:\Windows\assembly
2010-12-13 18:50:32 ----D---- C:\ProgramData\Microsoft Help
2010-12-13 18:49:27 ----D---- C:\Windows\system32\catroot
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files
2010-12-13 18:40:02 ----RSD---- C:\Windows\Fonts
2010-12-13 18:37:53 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-13 18:37:52 ----D---- C:\Program Files\Microsoft Office
2010-12-13 18:37:50 ----HD---- C:\ProgramData
2010-12-13 17:18:19 ----D---- C:\Windows\Logs
2010-12-13 13:11:06 ----D---- C:\Program Files\Mozilla Firefox
2010-12-13 11:57:11 ----D---- C:\Windows\Prefetch
2010-12-11 17:55:27 ----D---- C:\Windows\system32\WDI
2010-12-10 12:54:06 ----SD---- C:\Users\Notebook\AppData\Roaming\Microsoft
2010-12-10 12:37:49 ----SD---- C:\ProgramData\Microsoft
2010-12-10 12:37:18 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-25 17:41:29 ----D---- C:\Program Files\Internet Explorer
2010-11-25 17:40:39 ----D---- C:\Windows\system32\cs-CZ
2010-11-25 17:36:06 ----D---- C:\Windows\system32\en-US
2010-11-25 17:36:04 ----D---- C:\Program Files\Microsoft.NET
2010-11-23 18:51:28 ----D---- C:\Windows\system32\drivers
2010-11-15 19:36:15 ----D---- C:\Program Files\3DO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-12 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 al06i5e8;al06i5e8; C:\Windows\system32\drivers\al06i5e8.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-13 867080]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-13 79360]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
-----------------EOF-----------------
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
a jeste info
info.txt logfile of random's system information tool 1.08 2010-12-14 15:23:29
======Uninstall list======
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Agere Systems HDA Modem-->C:\Windows\agrsmdel
BitComet 1.21-->C:\Program Files\BitComet\uninst.exe
COSMOSM 2010 (2009/280)-->MsiExec.exe /I{1553E6CA-E99D-4885-A8BE-EF67342B859F}
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DWGeditor-->MsiExec.exe /X{56DCD20A-E558-4396-AF59-14D15AA737BB}
ESET Smart Security-->MsiExec.exe /I{6ECB944F-D027-4E8A-9906-70E77C005AD5}
Heroes of Might and Magic® III Complete-->C:\Windows\IsUninst.exe -f"C:\Program Files\3DO\Heroes 3 Complete\Heroes of Might and Magic® III.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.40 F1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0005 -removeonly uninst
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
K-Lite Mega Codec Pack 6.4.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
PDF24 Creator-->"C:\Program Files\pdf24\unins000.exe"
pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
PhotoView 360-->MsiExec.exe /I{736D2DAD-3D87-4CAA-8646-83D238AD68E0}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
SolidWorks 2010 SP0-->"C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM.exe" /remove "C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM_installed.xml"
SolidWorks 2010 SP0-->MsiExec.exe /X{AF2066F6-7C57-46A1-A306-077EBBFC7B2B}
SolidWorks eDrawings 2010-->MsiExec.exe /I{1959101B-E34C-4266-8915-20F23B5BCF43}
SolidWorks Explorer 2010 SP0-->MsiExec.exe /I{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}
SolidWorks Flow Simulation 2010 SP0-->MsiExec.exe /I{15041B8B-AC63-41DF-91D2-2118CE39E8D9}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SoundMAX-->C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe -runfromtemp -l0x0005 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Security center information======
AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender
======System event log======
Computer Name: Notebook-PC
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: Spuštěno
Record Number: 61587
Source Name: Service Control Manager
Time Written: 20100425210139.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu fdPHost s argumenty "" za účelem spuštění serveru:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
Record Number: 61586
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu hpqwmiex s argumenty "" za účelem spuštění serveru:
{F5539356-2F02-40D4-999E-FA61F45FE12E}
Record Number: 61585
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu netman s argumenty "" za účelem spuštění serveru:
{BA126AD1-2166-11D1-B1D0-00805FC1270E}
Record Number: 61584
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 14204
Message: Služba WMPNetworkSvc byla spuštěna.
Record Number: 61583
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 26L2233B1-13
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20091214081704.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 4
Source Name: Microsoft-Windows-EventSystem
Time Written: 20091214081700.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 900
Message: Služba Licencování softwaru se spouští.
Record Number: 3
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091214081659.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20091214081659.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 26L2233B1-13
Event Code: 2
Message: Klient Certifikační služby byl úspěšně zastaven.
Record Number: 1
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20080121025830.046400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 9573
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9572
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Účet, jehož pověření bylo použito:
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Cílový server:
Název cílového serveru: localhost
Další informace: localhost
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Síťová adresa: -
Port: -
Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 9571
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
Oprávnění: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 9570
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%COSMOSM%;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"COSMOSM"=C:\Program Files\SolidWorks Corp\COSMOS M
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2010-12-14 15:23:29
======Uninstall list======
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Agere Systems HDA Modem-->C:\Windows\agrsmdel
BitComet 1.21-->C:\Program Files\BitComet\uninst.exe
COSMOSM 2010 (2009/280)-->MsiExec.exe /I{1553E6CA-E99D-4885-A8BE-EF67342B859F}
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DWGeditor-->MsiExec.exe /X{56DCD20A-E558-4396-AF59-14D15AA737BB}
ESET Smart Security-->MsiExec.exe /I{6ECB944F-D027-4E8A-9906-70E77C005AD5}
Heroes of Might and Magic® III Complete-->C:\Windows\IsUninst.exe -f"C:\Program Files\3DO\Heroes 3 Complete\Heroes of Might and Magic® III.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.40 F1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0005 -removeonly uninst
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
K-Lite Mega Codec Pack 6.4.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
PDF24 Creator-->"C:\Program Files\pdf24\unins000.exe"
pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
PhotoView 360-->MsiExec.exe /I{736D2DAD-3D87-4CAA-8646-83D238AD68E0}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
SolidWorks 2010 SP0-->"C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM.exe" /remove "C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM_installed.xml"
SolidWorks 2010 SP0-->MsiExec.exe /X{AF2066F6-7C57-46A1-A306-077EBBFC7B2B}
SolidWorks eDrawings 2010-->MsiExec.exe /I{1959101B-E34C-4266-8915-20F23B5BCF43}
SolidWorks Explorer 2010 SP0-->MsiExec.exe /I{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}
SolidWorks Flow Simulation 2010 SP0-->MsiExec.exe /I{15041B8B-AC63-41DF-91D2-2118CE39E8D9}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SoundMAX-->C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe -runfromtemp -l0x0005 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Security center information======
AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender
======System event log======
Computer Name: Notebook-PC
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: Spuštěno
Record Number: 61587
Source Name: Service Control Manager
Time Written: 20100425210139.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu fdPHost s argumenty "" za účelem spuštění serveru:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
Record Number: 61586
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu hpqwmiex s argumenty "" za účelem spuštění serveru:
{F5539356-2F02-40D4-999E-FA61F45FE12E}
Record Number: 61585
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu netman s argumenty "" za účelem spuštění serveru:
{BA126AD1-2166-11D1-B1D0-00805FC1270E}
Record Number: 61584
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 14204
Message: Služba WMPNetworkSvc byla spuštěna.
Record Number: 61583
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 26L2233B1-13
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20091214081704.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 4
Source Name: Microsoft-Windows-EventSystem
Time Written: 20091214081700.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 900
Message: Služba Licencování softwaru se spouští.
Record Number: 3
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091214081659.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20091214081659.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 26L2233B1-13
Event Code: 2
Message: Klient Certifikační služby byl úspěšně zastaven.
Record Number: 1
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20080121025830.046400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 9573
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9572
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Účet, jehož pověření bylo použito:
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Cílový server:
Název cílového serveru: localhost
Další informace: localhost
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Síťová adresa: -
Port: -
Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 9571
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
Oprávnění: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 9570
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%COSMOSM%;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"COSMOSM"=C:\Program Files\SolidWorks Corp\COSMOS M
-----------------EOF-----------------
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
- HJT najdete zde C:\Program Files\trend micro\Notebook.exe
- Otevre se Vam okno, kliknete na Do a system scan only
- V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing) - Kliknete na Fix checked (vlevo dole)
- HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
staci kdyz volzim flashku?
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Ano, je to z duvodu ze havet muze byt i na ni a PC ji umi smazat...
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
tady je log z combofixu
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:16:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1559 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:20
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:22:21
ComboFix-quarantined-files.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 146 717 605 888
Po spuštění: Volných bajtů: 148 062 810 112
- - End Of File - - 9733DB0CDFAA7A4872823710CA6E0C7D
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:16:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1559 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:20
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:22:21
ComboFix-quarantined-files.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 146 717 605 888
Po spuštění: Volných bajtů: 148 062 810 112
- - End Of File - - 9733DB0CDFAA7A4872823710CA6E0C7D
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Collect:: C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job Folder:: C:\Program Files\DAEMON Tools Toolbar Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=- "{32099AAC-C132-4136-9E9A-4E364A424E17}"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200] "Metropolis"=- "JP595IR86O"=- Firefox:: FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\ FF - prefs.js: browser.search.selectedEngine - QIP Search FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query= FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com RegLock::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:40:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1703 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Notebook\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\install.rdf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:45
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:46:35
ComboFix-quarantined-files.txt 2010-12-14 16:46
ComboFix2.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 148 112 240 640
Po spuštění: Volných bajtů: 148 090 269 696
- - End Of File - - 5C9256E4DFA5961881EFD797BF9F0F05
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1703 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Notebook\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\install.rdf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:45
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:46:35
ComboFix-quarantined-files.txt 2010-12-14 16:46
ComboFix2.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 148 112 240 640
Po spuštění: Volných bajtů: 148 090 269 696
- - End Of File - - 5C9256E4DFA5961881EFD797BF9F0F05



Přispějete na provoz fóra?