
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Dobrý den. Mám problém s virem trojský kůň. Jako antivir používám Eset smart security. Při spuštění windowsů (Vista) mi vyskočí tabulka Run dll s textem: chyba při načítání souboru C:/windows/system 32/sshnas.21.dll - uvedený modul nebyl nalezen. Nevíte někdo co s tím aniž bych musel formátovat. Děkuji za odpověď
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Zdravim, pekne odpoledne preji a vitam Vas u nas na foru
Prectete si prosim pravidla fora
Havet to je, ale format nevyzaduje...
Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti, navic pri zatazenem pocasi jake ted v okrese Kromeriz panuje, neni nic videt
Ale dosti legracek, kouknem na to
Kliknete do meho podpisu na RSIT a dejte log z nej - navod Vas povede...







Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
mám obavy, že se v tom moc nevyznám co jste mi napsal 

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Abychom mohli urcit kde havet presne je, tak potrebuji log z RSIT - navod je zde http://www.viry.cz/forum/viewtopic.php?f=24&t=81939 - udelejte dle nej sken a log mi sem pak vlozte...
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Po ukonceni skenu se vytvori dva logy - log.txt a info.txt - oba dva my sem vlozte - pripadne budou ulozeny v c:\rsit
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
jeste mi to nedobehlo ten listing co mam delat?
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
jo uz to je
Logfile of random's system information tool 1.08 (written by random/random)
Run by Notebook at 2010-12-14 15:22:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 141 GB (59%) free of 238 GB
Total RAM: 3062 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:28, on 14.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\pdf24\pdf24.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\Downloads\RSIT.exe
C:\Program Files\trend micro\Notebook.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\Notebook\AppData\Local\Temp\Tvt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll/206 (file missing)
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9809 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll [2010-04-13 662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-10 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"PDFPrint"=C:\Program Files\pdf24\pdf24.exe [2010-03-11 208528]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-07-10 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"JP595IR86O"=C:\Users\Notebook\AppData\Local\Temp\Tvt.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-12-14 15:22:27 ----D---- C:\Program Files\trend micro
2010-12-14 15:22:26 ----D---- C:\rsit
2010-12-14 13:12:35 ----D---- C:\Program Files\MSXML 4.0
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-13 18:37:56 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-12-13 18:37:52 ----D---- C:\Program Files\AGEIA Technologies
2010-12-13 18:37:50 ----D---- C:\ProgramData\SolidWorks
2010-12-13 18:37:50 ----D---- C:\Program Files\SolidWorks Corp
2010-12-13 18:36:35 ----D---- C:\SolidWorks Data
2010-12-13 13:12:39 ----D---- C:\Users\Notebook\AppData\Roaming\BitComet
2010-12-13 13:12:39 ----D---- C:\Downloads
2010-12-13 13:11:42 ----D---- C:\Program Files\BitComet
2010-12-11 17:14:14 ----D---- C:\ProgramData\Macrovision
2010-12-10 13:01:21 ----D---- C:\ProgramData\FLEXnet
2010-12-10 12:56:36 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-12-10 12:36:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-12-10 12:36:12 ----D---- C:\Program Files\MSECache
2010-12-10 12:33:46 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2010-12-10 12:23:40 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-10 12:13:24 ----D---- C:\Windows\SolidWorks
2010-12-10 12:13:19 ----D---- C:\Users\Notebook\AppData\Roaming\SolidWorks
2010-11-23 18:56:52 ----D---- C:\Users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 18:56:45 ----D---- C:\ProgramData\progeSOFT
2010-11-23 18:52:59 ----A---- C:\Windows\system32\cdintf251.dll
2010-11-23 18:51:28 ----A---- C:\Windows\system32\drivers\eusk3usb.sys
2010-11-23 18:51:21 ----A---- C:\Windows\system32\vbar332.dll
2010-11-15 19:34:51 ----D---- C:\Program Files\Common Files\3DO Shared
======List of files/folders modified in the last 1 months======
2010-12-14 15:22:30 ----D---- C:\Windows\Temp
2010-12-14 15:22:27 ----RD---- C:\Program Files
2010-12-14 14:55:08 ----D---- C:\Windows\System32
2010-12-14 14:55:07 ----D---- C:\Windows\inf
2010-12-14 14:55:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-14 14:37:06 ----D---- C:\Windows
2010-12-14 13:31:28 ----SHD---- C:\System Volume Information
2010-12-14 13:13:45 ----SHD---- C:\Windows\Installer
2010-12-14 13:13:43 ----D---- C:\Windows\winsxs
2010-12-14 08:16:57 ----D---- C:\Windows\Tasks
2010-12-13 22:32:04 ----D---- C:\Windows\system32\Tasks
2010-12-13 19:10:44 ----D---- C:\Windows\system32\catroot2
2010-12-13 18:57:07 ----D---- C:\Windows\Microsoft.NET
2010-12-13 18:57:02 ----RSD---- C:\Windows\assembly
2010-12-13 18:50:32 ----D---- C:\ProgramData\Microsoft Help
2010-12-13 18:49:27 ----D---- C:\Windows\system32\catroot
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files
2010-12-13 18:40:02 ----RSD---- C:\Windows\Fonts
2010-12-13 18:37:53 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-13 18:37:52 ----D---- C:\Program Files\Microsoft Office
2010-12-13 18:37:50 ----HD---- C:\ProgramData
2010-12-13 17:18:19 ----D---- C:\Windows\Logs
2010-12-13 13:11:06 ----D---- C:\Program Files\Mozilla Firefox
2010-12-13 11:57:11 ----D---- C:\Windows\Prefetch
2010-12-11 17:55:27 ----D---- C:\Windows\system32\WDI
2010-12-10 12:54:06 ----SD---- C:\Users\Notebook\AppData\Roaming\Microsoft
2010-12-10 12:37:49 ----SD---- C:\ProgramData\Microsoft
2010-12-10 12:37:18 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-25 17:41:29 ----D---- C:\Program Files\Internet Explorer
2010-11-25 17:40:39 ----D---- C:\Windows\system32\cs-CZ
2010-11-25 17:36:06 ----D---- C:\Windows\system32\en-US
2010-11-25 17:36:04 ----D---- C:\Program Files\Microsoft.NET
2010-11-23 18:51:28 ----D---- C:\Windows\system32\drivers
2010-11-15 19:36:15 ----D---- C:\Program Files\3DO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-12 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 al06i5e8;al06i5e8; C:\Windows\system32\drivers\al06i5e8.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-13 867080]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-13 79360]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Notebook at 2010-12-14 15:22:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 141 GB (59%) free of 238 GB
Total RAM: 3062 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:28, on 14.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\pdf24\pdf24.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\AppData\Local\Seznam.cz\MiniBrowser.exe
C:\Users\Notebook\Downloads\RSIT.exe
C:\Program Files\trend micro\Notebook.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files\pdf24\pdf24.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Seznam Postak] "C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Metropolis] rundll32.exe C:\Windows\system32\sshnas21.dll,GetHandle
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\Notebook\AppData\Local\Temp\Tvt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll/206 (file missing)
O9 - Extra button: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Nastavení Lištičky ... - {0E46D7B6-887D-4F81-B4CA-FCC92AF73610} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (HKCU)
O9 - Extra button: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O9 - Extra 'Tools' menuitem: Zvýrazňovač slov Lištičky - {4E6D6F90-31CA-4878-A7A3-1CD50F115A69} - C:\Users\Notebook\AppData\Local\Seznam.cz\listicka.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{28C35D89-1E7F-455A-B8D0-5120ED3C30DA}: NameServer = 192.168.10.1
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Remote Solver for Flow Simulation 2010 - Mentor Graphics Corporation - C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 9809 bytes
======Scheduled tasks folder======
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.4.4.13.dll [2010-04-13 662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2009-07-14 150768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-10 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-05-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-05-22 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-05-22 133656]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-06-03 177456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-03-27 1045800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2007-02-21 1183744]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"PDFPrint"=C:\Program Files\pdf24\pdf24.exe [2010-03-11 208528]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-07-10 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"=C:\Users\Notebook\AppData\Local\Seznam.cz\postak.exe [2010-10-06 488728]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Metropolis"=C:\Windows\system32\sshnas21.dll,GetHandle []
"JP595IR86O"=C:\Users\Notebook\AppData\Local\Temp\Tvt.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-12-14 15:22:27 ----D---- C:\Program Files\trend micro
2010-12-14 15:22:26 ----D---- C:\rsit
2010-12-14 13:12:35 ----D---- C:\Program Files\MSXML 4.0
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-12-13 18:37:56 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2010-12-13 18:37:52 ----D---- C:\Program Files\AGEIA Technologies
2010-12-13 18:37:50 ----D---- C:\ProgramData\SolidWorks
2010-12-13 18:37:50 ----D---- C:\Program Files\SolidWorks Corp
2010-12-13 18:36:35 ----D---- C:\SolidWorks Data
2010-12-13 13:12:39 ----D---- C:\Users\Notebook\AppData\Roaming\BitComet
2010-12-13 13:12:39 ----D---- C:\Downloads
2010-12-13 13:11:42 ----D---- C:\Program Files\BitComet
2010-12-11 17:14:14 ----D---- C:\ProgramData\Macrovision
2010-12-10 13:01:21 ----D---- C:\ProgramData\FLEXnet
2010-12-10 12:56:36 ----A---- C:\Windows\eDrawingOfficeAutomator.INI
2010-12-10 12:36:56 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-12-10 12:36:12 ----D---- C:\Program Files\MSECache
2010-12-10 12:33:46 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2010-12-10 12:23:40 ----D---- C:\Program Files\Common Files\InstallShield
2010-12-10 12:13:24 ----D---- C:\Windows\SolidWorks
2010-12-10 12:13:19 ----D---- C:\Users\Notebook\AppData\Roaming\SolidWorks
2010-11-23 18:56:52 ----D---- C:\Users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 18:56:45 ----D---- C:\ProgramData\progeSOFT
2010-11-23 18:52:59 ----A---- C:\Windows\system32\cdintf251.dll
2010-11-23 18:51:28 ----A---- C:\Windows\system32\drivers\eusk3usb.sys
2010-11-23 18:51:21 ----A---- C:\Windows\system32\vbar332.dll
2010-11-15 19:34:51 ----D---- C:\Program Files\Common Files\3DO Shared
======List of files/folders modified in the last 1 months======
2010-12-14 15:22:30 ----D---- C:\Windows\Temp
2010-12-14 15:22:27 ----RD---- C:\Program Files
2010-12-14 14:55:08 ----D---- C:\Windows\System32
2010-12-14 14:55:07 ----D---- C:\Windows\inf
2010-12-14 14:55:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-14 14:37:06 ----D---- C:\Windows
2010-12-14 13:31:28 ----SHD---- C:\System Volume Information
2010-12-14 13:13:45 ----SHD---- C:\Windows\Installer
2010-12-14 13:13:43 ----D---- C:\Windows\winsxs
2010-12-14 08:16:57 ----D---- C:\Windows\Tasks
2010-12-13 22:32:04 ----D---- C:\Windows\system32\Tasks
2010-12-13 19:10:44 ----D---- C:\Windows\system32\catroot2
2010-12-13 18:57:07 ----D---- C:\Windows\Microsoft.NET
2010-12-13 18:57:02 ----RSD---- C:\Windows\assembly
2010-12-13 18:50:32 ----D---- C:\ProgramData\Microsoft Help
2010-12-13 18:49:27 ----D---- C:\Windows\system32\catroot
2010-12-13 18:47:53 ----D---- C:\Program Files\Common Files
2010-12-13 18:40:02 ----RSD---- C:\Windows\Fonts
2010-12-13 18:37:53 ----D---- C:\Program Files\Common Files\DESIGNER
2010-12-13 18:37:52 ----D---- C:\Program Files\Microsoft Office
2010-12-13 18:37:50 ----HD---- C:\ProgramData
2010-12-13 17:18:19 ----D---- C:\Windows\Logs
2010-12-13 13:11:06 ----D---- C:\Program Files\Mozilla Firefox
2010-12-13 11:57:11 ----D---- C:\Windows\Prefetch
2010-12-11 17:55:27 ----D---- C:\Windows\system32\WDI
2010-12-10 12:54:06 ----SD---- C:\Users\Notebook\AppData\Roaming\Microsoft
2010-12-10 12:37:49 ----SD---- C:\ProgramData\Microsoft
2010-12-10 12:37:18 ----D---- C:\Program Files\Common Files\microsoft shared
2010-11-25 17:41:29 ----D---- C:\Program Files\Internet Explorer
2010-11-25 17:40:39 ----D---- C:\Windows\system32\cs-CZ
2010-11-25 17:36:06 ----D---- C:\Windows\system32\en-US
2010-11-25 17:36:04 ----D---- C:\Program Files\Microsoft.NET
2010-11-23 18:51:28 ----D---- C:\Windows\system32\drivers
2010-11-15 19:36:15 ----D---- C:\Program Files\3DO
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-12 691696]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2008-04-24 309248]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-11-21 1204128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 HBtnKey;HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [2008-04-14 9344]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976]
R3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-03-27 199472]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 al06i5e8;al06i5e8; C:\Windows\system32\drivers\al06i5e8.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-02-06 69632]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2008-08-26 14336]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-13 867080]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-13 79360]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
-----------------EOF-----------------
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
a jeste info
info.txt logfile of random's system information tool 1.08 2010-12-14 15:23:29
======Uninstall list======
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Agere Systems HDA Modem-->C:\Windows\agrsmdel
BitComet 1.21-->C:\Program Files\BitComet\uninst.exe
COSMOSM 2010 (2009/280)-->MsiExec.exe /I{1553E6CA-E99D-4885-A8BE-EF67342B859F}
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DWGeditor-->MsiExec.exe /X{56DCD20A-E558-4396-AF59-14D15AA737BB}
ESET Smart Security-->MsiExec.exe /I{6ECB944F-D027-4E8A-9906-70E77C005AD5}
Heroes of Might and Magic® III Complete-->C:\Windows\IsUninst.exe -f"C:\Program Files\3DO\Heroes 3 Complete\Heroes of Might and Magic® III.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.40 F1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0005 -removeonly uninst
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
K-Lite Mega Codec Pack 6.4.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
PDF24 Creator-->"C:\Program Files\pdf24\unins000.exe"
pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
PhotoView 360-->MsiExec.exe /I{736D2DAD-3D87-4CAA-8646-83D238AD68E0}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
SolidWorks 2010 SP0-->"C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM.exe" /remove "C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM_installed.xml"
SolidWorks 2010 SP0-->MsiExec.exe /X{AF2066F6-7C57-46A1-A306-077EBBFC7B2B}
SolidWorks eDrawings 2010-->MsiExec.exe /I{1959101B-E34C-4266-8915-20F23B5BCF43}
SolidWorks Explorer 2010 SP0-->MsiExec.exe /I{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}
SolidWorks Flow Simulation 2010 SP0-->MsiExec.exe /I{15041B8B-AC63-41DF-91D2-2118CE39E8D9}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SoundMAX-->C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe -runfromtemp -l0x0005 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Security center information======
AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender
======System event log======
Computer Name: Notebook-PC
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: Spuštěno
Record Number: 61587
Source Name: Service Control Manager
Time Written: 20100425210139.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu fdPHost s argumenty "" za účelem spuštění serveru:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
Record Number: 61586
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu hpqwmiex s argumenty "" za účelem spuštění serveru:
{F5539356-2F02-40D4-999E-FA61F45FE12E}
Record Number: 61585
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu netman s argumenty "" za účelem spuštění serveru:
{BA126AD1-2166-11D1-B1D0-00805FC1270E}
Record Number: 61584
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 14204
Message: Služba WMPNetworkSvc byla spuštěna.
Record Number: 61583
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 26L2233B1-13
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20091214081704.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 4
Source Name: Microsoft-Windows-EventSystem
Time Written: 20091214081700.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 900
Message: Služba Licencování softwaru se spouští.
Record Number: 3
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091214081659.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20091214081659.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 26L2233B1-13
Event Code: 2
Message: Klient Certifikační služby byl úspěšně zastaven.
Record Number: 1
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20080121025830.046400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 9573
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9572
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Účet, jehož pověření bylo použito:
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Cílový server:
Název cílového serveru: localhost
Další informace: localhost
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Síťová adresa: -
Port: -
Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 9571
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
Oprávnění: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 9570
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%COSMOSM%;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"COSMOSM"=C:\Program Files\SolidWorks Corp\COSMOS M
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2010-12-14 15:23:29
======Uninstall list======
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Agere Systems HDA Modem-->C:\Windows\agrsmdel
BitComet 1.21-->C:\Program Files\BitComet\uninst.exe
COSMOSM 2010 (2009/280)-->MsiExec.exe /I{1553E6CA-E99D-4885-A8BE-EF67342B859F}
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DWGeditor-->MsiExec.exe /X{56DCD20A-E558-4396-AF59-14D15AA737BB}
ESET Smart Security-->MsiExec.exe /I{6ECB944F-D027-4E8A-9906-70E77C005AD5}
Heroes of Might and Magic® III Complete-->C:\Windows\IsUninst.exe -f"C:\Program Files\3DO\Heroes 3 Complete\Heroes of Might and Magic® III.isu" -c"C:\Program Files\Common Files\3DO Shared\3DOUnInst.dll
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Quick Launch Buttons 6.40 F1-->C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0005 -removeonly uninst
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Java(TM) 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
K-Lite Mega Codec Pack 6.4.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90120000-00A4-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Standard 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARD /dll OSETUP.DLL
Microsoft Office Standard 2007-->MsiExec.exe /X{90120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
Mozilla Firefox (3.5.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
PDF24 Creator-->"C:\Program Files\pdf24\unins000.exe"
pdfforge Toolbar v1.1.2-->MsiExec.exe /X{5791B7D3-8B34-4218-9750-6A8E45D0AD32}
PhotoView 360-->MsiExec.exe /I{736D2DAD-3D87-4CAA-8646-83D238AD68E0}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
SolidWorks 2010 SP0-->"C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM.exe" /remove "C:\Windows\SolidWorks\IM_20100-40000-1100-200\sldim\sldIM_installed.xml"
SolidWorks 2010 SP0-->MsiExec.exe /X{AF2066F6-7C57-46A1-A306-077EBBFC7B2B}
SolidWorks eDrawings 2010-->MsiExec.exe /I{1959101B-E34C-4266-8915-20F23B5BCF43}
SolidWorks Explorer 2010 SP0-->MsiExec.exe /I{2D8D14CC-5B31-44B9-87FC-BEC3D8AFFD1D}
SolidWorks Flow Simulation 2010 SP0-->MsiExec.exe /I{15041B8B-AC63-41DF-91D2-2118CE39E8D9}
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
SoundMAX-->C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe -runfromtemp -l0x0005 -removeonly
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Security center information======
AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender
======System event log======
Computer Name: Notebook-PC
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: Spuštěno
Record Number: 61587
Source Name: Service Control Manager
Time Written: 20100425210139.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu fdPHost s argumenty "" za účelem spuštění serveru:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
Record Number: 61586
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu hpqwmiex s argumenty "" za účelem spuštění serveru:
{F5539356-2F02-40D4-999E-FA61F45FE12E}
Record Number: 61585
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 10029
Message: Model DCOM spustil službu netman s argumenty "" za účelem spuštění serveru:
{BA126AD1-2166-11D1-B1D0-00805FC1270E}
Record Number: 61584
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
Computer Name: Notebook-PC
Event Code: 14204
Message: Služba WMPNetworkSvc byla spuštěna.
Record Number: 61583
Source Name: Microsoft-Windows-WMPNSS-Service
Time Written: 20100425210136.000000-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 26L2233B1-13
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 5
Source Name: Microsoft-Windows-WMI
Time Written: 20091214081704.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 4
Source Name: Microsoft-Windows-EventSystem
Time Written: 20091214081700.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 900
Message: Služba Licencování softwaru se spouští.
Record Number: 3
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091214081659.000000-000
Event Type: Informace
User:
Computer Name: WIN-Z1YZLTLKKPE
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20091214081659.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 26L2233B1-13
Event Code: 2
Message: Klient Certifikační služby byl úspěšně zastaven.
Record Number: 1
Source Name: Microsoft-Windows-CertificateServicesClient
Time Written: 20080121025830.046400-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 9573
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9572
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4648
Message: Došlo k pokusu o přihlášení pomocí explicitního pověření.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Účet, jehož pověření bylo použito:
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Cílový server:
Název cílového serveru: localhost
Další informace: localhost
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Síťová adresa: -
Port: -
Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při použití příkazu RUNAS.
Record Number: 9571
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092810.199739-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.
Předmět:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
Oprávnění: SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeImpersonatePrivilege
Record Number: 9570
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
Computer Name: Notebook-PC
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: NOTEBOOK-PC$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Typ přihlášení: 5
Nové přihlášení:
ID zabezpečení: S-1-5-19
Název účtu: LOCAL SERVICE
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e5
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x26c
Název procesu: C:\Windows\System32\services.exe
Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 9569
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100306092809.950137-000
Event Type: Úspěch auditu
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%COSMOSM%;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"COSMOSM"=C:\Program Files\SolidWorks Corp\COSMOS M
-----------------EOF-----------------
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen



- HJT najdete zde C:\Program Files\trend micro\Notebook.exe
- Otevre se Vam okno, kliknete na Do a system scan only
- V dalsim okne najdete radky které jsem Vam vypsal nize, vedle nich je ctverecek, do ktereho udelate zatrzitko
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Notebook\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing) - Kliknete na Fix checked (vlevo dole)
- HJT se Vas zepta zda opravdu ANO, s tim souhlasite a je hotovo

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Vložte do PC vsechny USB klice (flash disky, ext.disky apod.)
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
staci kdyz volzim flashku?
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
Ano, je to z duvodu ze havet muze byt i na ni a PC ji umi smazat...
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
tady je log z combofixu
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:16:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1559 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:20
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:22:21
ComboFix-quarantined-files.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 146 717 605 888
Po spuštění: Volných bajtů: 148 062 810 112
- - End Of File - - 9733DB0CDFAA7A4872823710CA6E0C7D
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:16:53.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1559 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Agere Systems Soft Modem - c:\windows\agrsmdel
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:20
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:22:21
ComboFix-quarantined-files.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 146 717 605 888
Po spuštění: Volných bajtů: 148 062 810 112
- - End Of File - - 9733DB0CDFAA7A4872823710CA6E0C7D
Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Collect:: C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job Folder:: C:\Program Files\DAEMON Tools Toolbar Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=- "{32099AAC-C132-4136-9E9A-4E364A424E17}"=- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200] "Metropolis"=- "JP595IR86O"=- Firefox:: FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\ FF - prefs.js: browser.search.selectedEngine - QIP Search FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query= FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com RegLock::
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

Re: C:/windows/system 32/sshnas.21.dll - modul nebyl nalezen
ComboFix 10-12-13.07 - Notebook 14.12.2010 17:40:45.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1703 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Notebook\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\install.rdf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:45
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:46:35
ComboFix-quarantined-files.txt 2010-12-14 16:46
ComboFix2.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 148 112 240 640
Po spuštění: Volných bajtů: 148 090 269 696
- - End Of File - - 5C9256E4DFA5961881EFD797BF9F0F05
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3062.1703 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\Notebook\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\extensions\DTToolbar@toolbarnet.com\install.rdf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-14 do 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-12-14 16:45 . 2010-12-14 16:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-14 14:22 . 2010-12-14 16:03 -------- d-----w- c:\program files\trend micro
2010-12-14 14:22 . 2010-12-14 14:23 -------- d-----w- C:\rsit
2010-12-14 12:14 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{246FAB05-F1CF-4DEF-9AAB-C2F19E95C092}\mpengine.dll
2010-12-14 12:12 . 2010-12-14 12:12 -------- d-----w- c:\program files\MSXML 4.0
2010-12-13 17:47 . 2010-12-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-12-13 17:37 . 2010-12-13 17:58 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2010-12-13 17:37 . 2010-12-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-12-13 17:37 . 2010-12-13 18:00 -------- d-----w- c:\program files\SolidWorks Corp
2010-12-13 17:37 . 2010-12-13 17:46 -------- d-----w- c:\programdata\SolidWorks
2010-12-13 17:36 . 2010-12-13 17:51 -------- d-----w- C:\SolidWorks Data
2010-12-13 14:53 . 2010-12-13 14:53 -------- d-----w- c:\users\Notebook\AppData\Local\ESET
2010-12-13 12:12 . 2010-12-13 19:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\BitComet
2010-12-13 12:12 . 2010-12-13 15:38 -------- d-----w- C:\Downloads
2010-12-13 12:11 . 2010-12-13 12:11 -------- d-----w- c:\program files\BitComet
2010-12-11 16:14 . 2010-12-11 16:14 -------- d-----w- c:\programdata\Macrovision
2010-12-10 12:01 . 2010-12-11 17:22 -------- d-----w- c:\programdata\FLEXnet
2010-12-10 11:36 . 2010-12-10 11:37 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-12-10 11:36 . 2010-12-10 11:36 -------- d-----w- c:\program files\MSECache
2010-12-10 11:33 . 2010-12-13 17:36 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2010-12-10 11:23 . 2010-12-10 11:23 -------- d-----w- c:\program files\Common Files\InstallShield
2010-12-10 11:13 . 2010-12-13 17:36 -------- d-----w- c:\windows\SolidWorks
2010-12-10 11:13 . 2010-12-10 12:01 -------- d-----w- c:\users\Notebook\AppData\Roaming\SolidWorks
2010-11-24 13:37 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-11-23 17:56 . 2010-11-23 17:56 -------- d-----w- c:\users\Notebook\AppData\Roaming\progeSOFT
2010-11-23 17:56 . 2010-11-23 17:57 -------- d-----w- c:\programdata\progeSOFT
2010-11-23 17:54 . 2009-04-15 13:59 431616 ----a-w- c:\windows\system32\temp.005
2010-11-23 17:54 . 2009-04-15 13:59 1392671 ----a-w- c:\windows\system32\temp.004
2010-11-23 17:53 . 2009-04-15 13:58 77878 ----a-w- c:\windows\system32\temp.002
2010-11-23 17:53 . 2009-04-15 13:58 69632 ----a-w- c:\windows\system32\temp.003
2010-11-23 17:53 . 2009-04-15 13:58 266293 ----a-w- c:\windows\system32\temp.001
2010-11-23 17:52 . 2009-04-15 13:57 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2010-11-23 17:52 . 2004-08-19 14:39 151552 ----a-w- c:\windows\system32\temp.000
2010-11-23 17:52 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2010-11-23 17:52 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2010-11-23 17:51 . 2009-04-15 13:58 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2010-11-23 17:51 . 2010-11-23 17:51 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2010-11-23 17:51 . 2001-03-13 14:49 140288 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-11-23 17:51 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2010-11-15 18:34 . 2010-11-15 18:36 -------- d-----w- c:\program files\Common Files\3DO Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 10:32 . 2010-11-12 10:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-19 09:41 . 2009-12-31 12:16 222080 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
R4 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
R4 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2009-09-11 144680]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-12 691696]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\2otdff09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: BitComet Video Downloader: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB} - %profile%\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-14 17:45
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Celkový čas: 2010-12-14 17:46:35
ComboFix-quarantined-files.txt 2010-12-14 16:46
ComboFix2.txt 2010-12-14 16:22
Před spuštěním: Volných bajtů: 148 112 240 640
Po spuštění: Volných bajtů: 148 090 269 696
- - End Of File - - 5C9256E4DFA5961881EFD797BF9F0F05