Po zkopírování textu z okénka jem vložil text do poznámkového bloku a postupoval podle Vaších instrukcí.Po přetažení skriptu a pustění jsem musel kliknout na spuštění ComboFix-u.Po té na mně postupně začaly vybafovat různá okénka,kde jsem klikal na "ano" (bylo psáno v angličtině,kterou ztěží ovládám

).Potom už začal ComboFix scanovat a vytvořil log.Doufám,že jsem vše dělal správně.Vždy ve mně tlí nějaká nejistota

.
ComboFix 10-12-13.02 - Otakar Vavrečka 14.12.2010 6:53.6.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3066.2053 [GMT 1:00]
Running from: c:\users\Otakar Vavrečka\Desktop\ComboFix.exe
Command switches used :: c:\users\Otakar Vavrečka\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\datastore\cache.sqlite
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\defaults.js.bak
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\defaults\preferences\defaults.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome.manifest
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\about.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\about.xul
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\cache.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\constants.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\core.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\custom-command-listener.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\events.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\feeds.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\json.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\lifecycle.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\listeners.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\locale.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\logger.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\network.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\observer.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\options.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\options.xul
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\preferences.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\prefetch.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\ss-popup-bindings.xml
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\suggestions.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\update.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\utilities.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\webframe-bindings.xml
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\webframe-manager.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\widget-controller.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\widget-popup.xul
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\content\widgets.js
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\abc.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\amazon_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\as.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\ask_16x16.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\ask_32x32.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\ask_browser_ff_chrome.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\asklogo.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\bbc_news.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\beppe_grillo.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\bg.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\bild.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\blogs.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\business.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\celebrity.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\close.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\cnn_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\corriere_della_sera.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\dictionary.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\el_mundo.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\email_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\expansion.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\facebook_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\folha.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\ft.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\ftd.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\g1.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\games_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\gazzetta_dello_sport.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\globe_18x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\gripper.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\highlight_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\highlighter_off.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\highlighter_on.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\hola.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\chevron.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_film1_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_history_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_news_ru_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_nu_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_radiodigital_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_sports_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_sportsru_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icon_vk_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\icons_business_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\images.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\kicker.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-de.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-en.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-es.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-fr.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-it.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-nl.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-pt.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\labels-ru.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\laposte.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\lemonde.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\lequipe.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\libero_it.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-BR.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-DE.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-ES.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-EU.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-FR.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-IT.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-NL.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-RU.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-UK.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\links-US.properties
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\logo_32x32.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\magnify_search.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\magnify_search_grey_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\maps.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\mtv.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\news.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\oglobo.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\orkut.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\personas.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\preferences.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_de.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_es.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_fr.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_it.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_nl.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_pl.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_pt.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ask_ru.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_cobrand.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_current_site.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_de.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_es.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_fr.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_grey_73x24.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_it.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_nl.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_pl.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_pt.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\search_ru.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\shopping.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\sports.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\stocks.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\terra.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\titlebar_bg.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\toolbar.css
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\toolbar.xul
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\tv.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\tv_movie_de.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\uol.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\voici_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\weather.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\weather_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\web.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\web_de.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\wordoftheday_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\youtube_16x.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\skin\zoomall.png
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\temp\askToolbar.exe
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Fri-22-Oct-2010-10-47-17-GMT\ff-config.zip
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Thu-30-Sep-2010-12-12-25-GMT\ff-config.zip
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-07-Dec-2010-19-26-42-GMT\ff-config.zip
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-28-Sep-2010-18-57-36-GMT\ff-config.zip
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\install.rdf
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292252654658.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292252657668.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292252802396.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292252805328.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267107915.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267114695.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267332703.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267452603.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267453655.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292267453768.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292270900586.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292271704180.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\logs\asktb-log-1292305192561.html
c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\extensions\
toolbar@ask.com\searchplugins\askcom.xml
.
((((((((((((((((((((((((( Files Created from 2010-11-14 to 2010-12-14 )))))))))))))))))))))))))))))))
.
2010-12-14 05:59 . 2010-12-14 05:59 -------- d-----w- c:\users\Otakar Vavrečka\AppData\Local\temp
2010-12-14 05:59 . 2010-12-14 05:59 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-12-14 05:59 . 2010-12-14 05:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-12-13 20:17 . 2010-12-13 20:17 -------- d-----w- c:\users\Otakar Vavrečka\AppData\Roaming\vlc
2010-12-13 20:16 . 2010-12-13 20:16 -------- d-----w- c:\program files\VideoLAN
2010-12-13 08:17 . 2010-12-13 08:17 420920 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-12-12 07:41 . 2010-12-12 07:41 -------- d-----w- c:\users\Otakar Vavrečka\AppData\Roaming\Malwarebytes
2010-12-12 07:41 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-12 07:41 . 2010-12-12 07:41 -------- d-----w- c:\programdata\Malwarebytes
2010-12-12 07:41 . 2010-12-12 07:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-12 07:41 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-11 17:08 . 2010-12-11 18:17 -------- d-sh--w- c:\programdata\IAHBV
2010-12-11 17:07 . 2010-12-11 18:17 -------- d-sh--w- c:\programdata\384e50
2010-12-10 08:09 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{368EEB72-967E-4AF6-A2AC-DE802CC89811}\mpengine.dll
2010-11-28 05:35 . 2010-11-28 05:50 53248 ----a-w- c:\windows\system32\drivers\rk_remover.sys
2010-11-24 06:09 . 2010-10-19 08:10 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-09 06:49 . 2010-04-12 08:49 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-23 17:34 . 2010-04-12 08:49 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-19 09:41 . 2010-04-12 09:01 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\tbMyA0.dll" [2010-09-28 2735200]
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
2010-09-28 08:36 2735200 ----a-w- c:\program files\MyAshampoo\tbMyA0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}"= "c:\program files\MyAshampoo\tbMyA0.dll" [2010-09-28 2735200]
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}"= "c:\program files\MyAshampoo\tbMyA0.dll" [2010-09-28 2735200]
[HKEY_CLASSES_ROOT\clsid\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-07-16 1668664]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
"eyeBeam SIP Client"="c:\program files\CounterPath\X-Lite\x-lite.exe" [2010-01-04 23941120]
"Google Update"="c:\users\Otakar Vavrečka\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-08-24 135664]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-24 39408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-10-19 328056]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-25 186904]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-06 281768]
"KONICA MINOLTA PagePro 1300WStatusDisplay"="c:\windows\system32\MSTMON_N.EXE" [2004-11-25 151552]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"PTHOSTTR"="c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2009-07-30 354360]
"CognizanceTS"="c:\progra~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2009-07-23 24848]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-03 98304]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
c:\users\Otakar Vavreźka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 795936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\HEWLET~1\IAM\Bin\APSHook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-24 135664]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2003-07-19 18848]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe [2009-07-30 45056]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 rk_remover-boot;rk_remover-boot;c:\windows\system32\drivers\rk_remover.sys [2010-11-28 53248]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-22 1343400]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-13 420920]
S0 SafeBoot;SafeBoot; [x]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 RsvLock;RsvLock; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-08-04 176128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-06 135336]
S2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\Advanced System Optimizer 3\ASO3DefragSrv.exe [2010-09-27 239928]
S2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [2009-07-29 1201400]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-07-29 256544]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2010-06-15 26168]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-06-02 246520]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S3 5U876UVC;HP Webcam [2 MP series];c:\windows\system32\DRIVERS\5U876.sys [2009-06-30 12:01 118656]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-08-04 6096384]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-08-04 214016]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
yksvcs REG_MULTI_SZ yksvc
GPSvcGroup REG_MULTI_SZ GPSvc
Cognizance REG_MULTI_SZ ASBroker
Bioscrypt REG_MULTI_SZ ASChannel
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-24 18:50]
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-24 18:50]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = http=127.0.0.1:25397
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
FF - ProfilePath - c:\users\Otakar Vavrečka\AppData\Roaming\Mozilla\Firefox\Profiles\dnr21fna.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyAshampoo Toolbar: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - %profile%\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}
.
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.1.7600 Disk: Hitachi_ rev.FC4O -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: >>UNKNOWN [0x82E38000]<< >>UNKNOWN [0x8BC07000]<< >>UNKNOWN [0x8CA83000]<< >>UNKNOWN [0x8CA48000]<< >>UNKNOWN [0x82E01000]<< >>UNKNOWN [0x8BD16000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x82E74458] -> \Device\Harddisk0\DR0[0x8757D6B0]
\Driver\Disk[0x8757EC38] -> IRP_MJ_CREATE -> 0x8BC0B39F
3 [0x8BC0B59E] -> ntkrnlpa!IofCallDriver[0x82E74458] -> [0x8757D030]
\Driver\hpdskflt[0x8752F450] -> IRP_MJ_CREATE -> 0x8CA49FB0
5 [0x8CA4A090] -> ntkrnlpa!IofCallDriver[0x82E74458] -> \Device\Ide\IAAStorageDevice-1[0x86AC0038]
\Driver\iaStor[0x86B09498] -> IRP_MJ_CREATE -> 0x8BD5A954
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-12-14 07:01:01
ComboFix-quarantined-files.txt 2010-12-14 06:01
ComboFix2.txt 2010-12-12 10:37
ComboFix3.txt 2010-11-26 23:00
ComboFix4.txt 2010-11-14 12:00
ComboFix5.txt 2010-12-14 05:52
Pre-Run: 131 975 241 728 bytes free
Post-Run: 131 926 691 840 bytes free
- - End Of File - - D673741EB12C79138C4C17120D3020F9