Stránka 2 z 3

Re: Delta Search

Napsal: 12 bře 2013 09:03
od vyosek
:arrow: Zapojte do PC vsechny USB klice (flashky, ext. disky apod.) :arrow: Spustte znovu OTL
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    :otl
    DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
    DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsnpfd.sys -- (dsnpfdMP)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Peter\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\TBPANEL.SYS -- (Cardex)
    DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=1195 ... 21855d186e
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=1195 ... 21855d186e
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.google.com
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 30 E6 DA 84 E8 18 CD 01 [binary data]
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,BrowserMngrDefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119520&babsrc=SP_ss&mntrId=7a19965c0000000000000021855d186e
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{1D7662A0-5BCA-4052-8EE8-276CD182692A}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
    IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7IRFC_sk
    FF - prefs.js..browser.search.selectedEngine: "Delta Search"
    FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119520&babsrc=HP_ss&mntrId=7a19965c0000000000000021855d186e"¨
    [2013/02/27 22:03:15 | 000,006,484 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\a30emazl.default\searchplugins\BrowserProtect.xml
    [2013/02/27 22:03:27 | 000,001,294 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\a30emazl.default\searchplugins\delta.xml
    O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
    O3 - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
    O33 - MountPoints2\{196bd9c0-c139-11de-832a-0021855d186e}\Shell - "" = AutoRun
    [2013/02/27 22:03:26 | 000,000,000 | ---D | C] -- C:\Program Files\Delta
    [2013/02/27 22:03:23 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Delta
    [4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [5 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
    [2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
    [2013/03/02 11:37:06 | 000,000,350 | ---- | M] () -- C:\Windows\Tasks\AddLyrics update.job
    [2013/03/02 14:39:28 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
    [2013/03/02 11:36:54 | 000,000,920 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    [2013/03/02 14:02:00 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    [2013/03/01 15:35:00 | 000,000,894 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004Core.job
    [2013/03/02 14:35:15 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004UA.job
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"=-
    "UpdateLBPShortCut"=-
    "MDS_Menu"=-
    "CLMLServer"=-
    "UpdateP2GoShortCut"=-
    "RemoteControl8"=-
    "PDVD8LanguageShortcut"=-
    "BDRegion"-
    "UpdatePPShortCut"=-
    "UCam_Menu"=-
    "LGODDFU"=-
    "UpdatePSTShortCut"=-
    "Adobe ARM"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"=-
    "WMPNSCFG"=-
    "Skype"=-
    
    :files
    C:\Program Files\Delta
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [EMPTYJAVA]
  • Nasledne kliknete na Opravit
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Delta Search

Napsal: 12 bře 2013 21:17
od Huso
Zatial log z usbfix:

############################## | UsbFix V 7.096 | [Deletion]

User: Peter (Administrator) # PETERPC
Updated 15/08/2012 by El Desaparecido
Started at 21:04:25 | 12/03/2013

Website: http://eldesaparecido.com
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com

PC: MICRO-STAR INTERNATIONAL CO.,LTD (MS-7519) (X86-based PC) # Desktop Computer
CPU: Intel(R) Core(TM)2 Duo CPU E8500 @ 3.16GHz (3166)
RAM -> [Total : 3070 | Free : 1531]
BIOS: Default System BIOS
BOOT: Normal boot

OS: Microsoft® Windows Vista™ Home Premium (6.0.6002 32-Bit) # Service Pack 2
WB: Windows Internet Explorer 9.0.8112.16421

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Kaspersky Anti-Virus [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 466 Gb (3 Mb free - 1%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Removable drive # 2 Gb (71 Mb free - 4%) [UDISK] # FAT32
J:\ -> CD-ROM
K:\ -> Fixed drive # 932 Gb (360 Mb free - 39%) [USB-HDD] # NTFS

################## | Active Processes |

C:\Windows\system32\csrss.exe (664)
C:\Windows\system32\wininit.exe (724)
C:\Windows\system32\csrss.exe (732)
C:\Windows\system32\services.exe (768)
C:\Windows\system32\lsass.exe (780)
C:\Windows\system32\lsm.exe (788)
C:\Windows\system32\winlogon.exe (864)
C:\Windows\system32\svchost.exe (964)
C:\Windows\system32\nvvsvc.exe (1008)
C:\Windows\system32\svchost.exe (1044)
C:\Windows\System32\svchost.exe (1080)
C:\Windows\System32\svchost.exe (1212)
C:\Windows\System32\svchost.exe (1240)
C:\Windows\system32\svchost.exe (1260)
C:\Windows\system32\svchost.exe (1368)
C:\Windows\system32\SLsvc.exe (1392)
C:\Windows\system32\svchost.exe (1416)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1600)
C:\Windows\system32\nvvsvc.exe (1612)
C:\Windows\system32\svchost.exe (1664)
C:\Windows\System32\spoolsv.exe (1848)
C:\Windows\system32\svchost.exe (1876)
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (648)
C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (500)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1024)
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1328)
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (1548)
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (1748)
C:\Program Files\Bonjour\mDNSResponder.exe (1884)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (196)
C:\Program Files\Microsoft LifeCam\MSCamS32.exe (2040)
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (2112)
C:\Windows\system32\svchost.exe (2176)
C:\Program Files\CyberLink\Shared files\RichVideo.exe (2188)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (2276)
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2292)
C:\Windows\system32\svchost.exe (2328)
C:\Windows\System32\svchost.exe (2360)
C:\Windows\system32\SearchIndexer.exe (2412)
C:\Windows\System32\WUDFHost.exe (2600)
C:\Windows\system32\taskeng.exe (2644)
C:\Windows\system32\Dwm.exe (2892)
C:\Windows\system32\taskeng.exe (3028)
C:\Program Files\Windows Defender\MSASCui.exe (4024)
C:\Windows\RtHDVCpl.exe (4036)
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (4052)
C:\Genius\ioCentre\gTaskBar.exe (4072)
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (264)
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (2168)
C:\Program Files\CyberLink\Shared files\brs.exe (2480)
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (2704)
C:\Program Files\NetWorx\networx.exe (2912)
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (876)
C:\Program Files\Windows Sidebar\sidebar.exe (2840)
C:\Windows\ehome\ehtray.exe (3044)
C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (2964)
C:\Program Files\Windows Media Player\wmpnscfg.exe (3216)
C:\Program Files\Skype\Phone\Skype.exe (2252)
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe (3364)
C:\Program Files\Windows Media Player\wmpnetwk.exe (3348)
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (1772)
C:\Windows\ehome\ehmsas.exe (3368)
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN (12)
C:\Windows\system32\wbem\unsecapp.exe (3576)
C:\Windows\system32\wbem\wmiprvse.exe (3344)
C:\Windows\system32\SearchProtocolHost.exe (3556)
C:\Genius\ioCentre\gMouseTask.exe (2160)
C:\Genius\ioCentre\gKbdTask.exe (3892)
C:\Genius\ioCentre\gAutoPan.exe (2848)
C:\Genius\ioCentre\gAutoScroll.exe (316)
C:\Genius\ioCentre\gZoom.exe (3580)
C:\Genius\ioCentre\gIMMgm.exe (3904)
C:\Genius\ioCentre\gKbStatus.exe (4004)
C:\Genius\ioCentre\gDeskMgm.exe (900)
C:\Genius\ioCentre\gTaskSwitch.exe (3528)
C:\Genius\ioCentre\gAutoScroll.exe (4300)
C:\Windows\system32\svchost.exe (5956)
C:\Windows\Explorer.EXE (4232)
C:\UsbFix\Go.exe (5564)
C:\Windows\system32\wbem\wmiprvse.exe (4508)
C:\Windows\system32\SearchFilterHost.exe (5900)

################## | Stopped processes |

Stopped! C:\Windows\system32\nvvsvc.exe (1008)
Stopped! C:\Windows\system32\SLsvc.exe (1392)
Stopped! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1600)
Stopped! C:\Windows\system32\nvvsvc.exe (1612)
Stopped! C:\Windows\System32\spoolsv.exe (1848)
Stopped! C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (648)
Stopped! C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (500)
Stopped! C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1024)
Stopped! C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1328)
Stopped! C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (1548)
Stopped! C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (1748)
Stopped! C:\Program Files\Bonjour\mDNSResponder.exe (1884)
Stopped! C:\Program Files\Common Files\LightScribe\LSSrvc.exe (196)
Stopped! C:\Program Files\Microsoft LifeCam\MSCamS32.exe (2040)
Stopped! C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (2112)
Stopped! C:\Program Files\CyberLink\Shared files\RichVideo.exe (2188)
Stopped! c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (2276)
Stopped! c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (2292)
Stopped! C:\Windows\system32\SearchIndexer.exe (2412)
Stopped! C:\Windows\System32\WUDFHost.exe (2600)
Stopped! C:\Windows\system32\taskeng.exe (2644)
Stopped! C:\Windows\system32\taskeng.exe (3028)
Stopped! C:\Program Files\Windows Defender\MSASCui.exe (4024)
Stopped! C:\Windows\RtHDVCpl.exe (4036)
Stopped! C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (4052)
Stopped! C:\Genius\ioCentre\gTaskBar.exe (4072)
Stopped! C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (264)
Stopped! C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe (2168)
Stopped! C:\Program Files\CyberLink\Shared files\brs.exe (2480)
Stopped! C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (2704)
Stopped! C:\Program Files\NetWorx\networx.exe (2912)
Stopped! C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe (876)
Stopped! C:\Program Files\Windows Sidebar\sidebar.exe (2840)
Stopped! C:\Windows\ehome\ehtray.exe (3044)
Stopped! C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (2964)
Stopped! C:\Program Files\Windows Media Player\wmpnscfg.exe (3216)
Stopped! C:\Program Files\Skype\Phone\Skype.exe (2252)
Stopped! C:\Program Files\OpenOffice.org 2.1\program\soffice.exe (3364)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (3348)
Stopped! C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (1772)
Stopped! C:\Windows\ehome\ehmsas.exe (3368)
Stopped! C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN (12)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (3556)
Stopped! C:\Genius\ioCentre\gMouseTask.exe (2160)
Stopped! C:\Genius\ioCentre\gKbdTask.exe (3892)
Stopped! C:\Genius\ioCentre\gAutoPan.exe (2848)
Stopped! C:\Genius\ioCentre\gAutoScroll.exe (316)
Stopped! C:\Genius\ioCentre\gZoom.exe (3580)
Stopped! C:\Genius\ioCentre\gIMMgm.exe (3904)
Stopped! C:\Genius\ioCentre\gKbStatus.exe (4004)
Stopped! C:\Genius\ioCentre\gDeskMgm.exe (900)
Stopped! C:\Genius\ioCentre\gTaskSwitch.exe (3528)
Stopped! C:\Genius\ioCentre\gAutoScroll.exe (4300)
Stopped! C:\Windows\system32\SearchFilterHost.exe (5900)

################## | Files # Infected Folders |

Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2392522767-3960030484-1258025880-1004
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2392522767-3960030484-1258025880-1004
Deleted ! K:\autorun.inf

(!) Temporary files deleted.

################## | Registry |


################## | Mountpoints2 |


################## | Listing |

[12/03/2013 - 21:12:17 | SHD ] C:\$Recycle.Bin
[08/07/2009 - 17:56:53 | D ] C:\5ad9ce897fb02afe679254
[10/07/2009 - 20:58:24 | D ] C:\7e9f9127c4944877df1174215fbcd2
[16/01/2013 - 19:58:11 | | 12267] C:\AdwCleaner[R1].txt
[02/03/2013 - 08:53:21 | | 4709] C:\AdwCleaner[R2].txt
[10/03/2013 - 20:54:39 | | 1961] C:\AdwCleaner[R3].txt
[16/01/2013 - 21:08:06 | | 12898] C:\AdwCleaner[S1].txt
[02/03/2013 - 11:31:43 | | 5068] C:\AdwCleaner[S2].txt
[10/03/2013 - 20:57:12 | | 1857] C:\AdwCleaner[S3].txt
[27/02/2013 - 23:33:12 | D ] C:\audiograbber
[18/09/2006 - 22:43:36 | | 24] C:\autoexec.bat
[12/03/2013 - 20:03:33 | RASHD ] C:\Autorun.inf
[15/07/2009 - 21:35:07 | SHD ] C:\Boot
[11/04/2009 - 07:36:36 | RASH | 333257] C:\bootmgr
[10/03/2013 - 11:35:47 | D ] C:\Config.Msi
[18/09/2006 - 22:43:37 | | 10] C:\config.sys
[02/11/2006 - 14:02:03 | SHD ] C:\Documents and Settings
[08/07/2009 - 19:00:46 | D ] C:\Genius
[12/03/2013 - 20:18:55 | ASH | 3220365312] C:\hiberfil.sys
[27/11/2008 - 17:46:41 | D ] C:\Intel
[27/11/2008 - 18:05:06 | | 0] C:\IO.SYS
[02/03/2013 - 08:58:33 | | 4709] C:\log AdwCleaner 02032013.txt
[18/10/2011 - 18:26:04 | D ] C:\Milan50
[27/11/2008 - 18:05:06 | | 0] C:\MSDOS.SYS
[27/11/2008 - 18:09:35 | RHD ] C:\MSOCache
[12/11/2009 - 11:27:31 | N | 262144] C:\ntuser.dat
[12/11/2009 - 11:27:31 | | 5120] C:\ntuser.dat.LOG1
[01/07/2009 - 20:48:25 | | 0] C:\ntuser.dat.LOG2
[01/07/2009 - 20:48:25 | | 65536] C:\ntuser.dat{6133f0f5-666a-11de-ad89-0021855d186e}.TM.blf
[01/07/2009 - 20:48:25 | | 524288] C:\ntuser.dat{6133f0f5-666a-11de-ad89-0021855d186e}.TMContainer00000000000000000001.regtrans-ms
[01/07/2009 - 20:48:25 | | 524288] C:\ntuser.dat{6133f0f5-666a-11de-ad89-0021855d186e}.TMContainer00000000000000000002.regtrans-ms
[12/11/2009 - 11:27:31 | | 65536] C:\ntuser.dat{6133f0fa-666a-11de-ad89-0021855d186e}.TM.blf
[12/11/2009 - 11:27:31 | | 524288] C:\ntuser.dat{6133f0fa-666a-11de-ad89-0021855d186e}.TMContainer00000000000000000001.regtrans-ms
[01/07/2009 - 20:48:26 | | 524288] C:\ntuser.dat{6133f0fa-666a-11de-ad89-0021855d186e}.TMContainer00000000000000000002.regtrans-ms
[12/12/2008 - 17:47:25 | D ] C:\NVIDIA
[12/03/2013 - 20:18:34 | ASH | 3533971456] C:\pagefile.sys
[11/07/2009 - 02:15:58 | D ] C:\PerfLogs
[02/03/2013 - 14:20:24 | | 512] C:\PhysicalMBR.bin
[10/03/2013 - 14:16:04 | D ] C:\Program Files
[10/03/2013 - 14:25:53 | HD ] C:\ProgramData
[11/03/2013 - 06:21:04 | D ] C:\rsit
[12/03/2013 - 19:59:44 | SHD ] C:\System Volume Information
[19/11/2012 - 00:12:07 | D ] C:\Temp
[12/03/2013 - 21:12:17 | D ] C:\UsbFix
[12/03/2013 - 21:04:46 | A | 11701] C:\UsbFix.txt
[12/03/2013 - 20:03:42 | D ] C:\UsbFix_Upload_Me
[01/07/2009 - 16:01:12 | D ] C:\Users
[12/03/2013 - 20:13:03 | D ] C:\Windows
[05/03/2013 - 16:39:54 | N | 5034430] E:\20130204_114353.mp4
[20/01/2013 - 22:45:16 | N | 13192704] E:\Manual 2013.doc
[05/03/2013 - 16:40:00 | N | 22446767] E:\20130204_090737.mp4
[20/01/2012 - 13:46:52 | D ] E:\Opatrenie KH
[14/10/2011 - 16:05:24 | D ] E:\Opatrenia vykazy BR1
[31/07/2012 - 19:42:56 | D ] E:\LOST.DIR
[09/09/2012 - 19:26:28 | D ] E:\u2
[29/05/2009 - 15:24:04 | N | 1888256] E:\~WRL3612.tmp
[05/03/2013 - 16:40:18 | N | 43683540] E:\20130204_090706.mp4
[03/06/2009 - 14:00:30 | N | 1890304] E:\~WRL2596.tmp
[16/10/2011 - 23:01:06 | D ] E:\opatrenie nbs vykazy
[03/06/2009 - 16:00:58 | N | 31744] E:\~WRL2099.tmp
[18/04/2010 - 18:26:16 | N | 172] E:\DRMv1PM.lic
[11/01/2012 - 23:32:46 | D ] E:\Vyhlaska NBS DIT_DIS_novela
[05/03/2013 - 16:40:20 | N | 2503841] E:\20130204_084701.jpg
[03/11/2011 - 18:58:12 | N | 165] E:\~$husovica.pptx
[21/12/2012 - 11:34:28 | D ] E:\DIMENZIE
[05/03/2013 - 16:40:20 | N | 2885796] E:\20130204_084748.jpg
[15/06/2010 - 08:14:22 | N | 14722] E:\zapisnica_23_11_09.docx
[15/06/2010 - 11:37:24 | N | 15716] E:\zapisnica_14_6_10.docx
[05/03/2013 - 16:40:20 | N | 2576822] E:\20130204_084800.jpg
[05/03/2013 - 16:40:22 | N | 2399070] E:\20130204_084811.jpg
[10/03/2013 - 17:13:38 | N | 23588749] E:\20130206_214152.mp4
[05/03/2013 - 16:40:38 | N | 27826485] E:\20130204_075305.mp4
[05/03/2013 - 16:41:10 | N | 76509754] E:\20130204_075113.mp4
[05/03/2013 - 16:41:12 | N | 3604284] E:\20130204_073846.jpg
[28/07/2010 - 00:17:18 | N | 259072] E:\o co ide Working Paper No 12-1.doc
[12/12/2011 - 00:33:28 | N | 100352] E:\04-Vyhodnotenie MPK opatreni vykazy do LK.doc
[24/08/2012 - 15:21:58 | D ] E:\Ocp_PIS_02_04
[12/01/2012 - 16:21:02 | N | 1015296] E:\ocenovacka 20120105_draft_v1_SF.doc
[15/01/2012 - 22:55:24 | D ] E:\Opatrnie NBS DIT_DIS_novela
[05/03/2013 - 16:41:12 | N | 3176216] E:\20130204_073804.jpg
[05/03/2013 - 16:41:14 | N | 3455414] E:\20130204_073752.jpg
[31/07/2012 - 19:42:56 | D ] E:\.android_secure
[13/09/2012 - 12:19:38 | N | 58880] E:\list_ORA_9617_2012_AEGON DDF_ výklad zákona.doc
[13/09/2012 - 12:20:00 | N | 26243] E:\list_ORA_9617_2012_AEGON DDF_ výklad zákona.docx
[07/11/2012 - 18:32:08 | N | 12627456] E:\Samko jablone.doc
[09/03/2009 - 16:16:00 | D ] E:\referaty
[05/03/2013 - 16:41:14 | N | 2498889] E:\20130203_201952.jpg
[11/12/2012 - 17:55:30 | N | 22551] E:\Informačné povinnosti.docx
[13/12/2012 - 18:07:24 | N | 26313] E:\Informačné povinnosti13_12_2012.docx
[17/12/2012 - 15:22:34 | D ] E:\Dátový model
[05/03/2013 - 16:41:14 | N | 2129922] E:\20130203_201925.jpg
[05/03/2013 - 16:41:14 | N | 2709072] E:\20130203_201911.jpg
[05/03/2013 - 16:41:16 | N | 3741430] E:\20130202_163049.jpg
[05/03/2013 - 16:41:18 | N | 3527782] E:\20130202_163057.jpg
[05/03/2013 - 16:41:22 | N | 3823616] E:\20130202_163107.jpg
[05/03/2013 - 16:41:26 | N | 2120862] E:\20130203_201858.jpg
[05/03/2013 - 16:41:30 | N | 3663803] E:\20130202_163042.jpg
[05/03/2013 - 16:41:36 | N | 3538591] E:\20130202_163036.jpg
[05/03/2013 - 16:41:38 | N | 2942022] E:\20130202_163022.jpg
[05/03/2013 - 16:42:48 | N | 2685190] E:\20130202_163015.jpg
[17/02/2011 - 10:47:04 | D ] E:\del
[05/03/2013 - 16:42:48 | N | 2729826] E:\20130202_162931.jpg
[05/03/2013 - 16:42:50 | N | 2641804] E:\20130202_162941.jpg
[05/03/2013 - 16:42:50 | N | 2614515] E:\20130202_162955.jpg
[05/03/2013 - 16:42:50 | N | 2573070] E:\20130202_163000.jpg
[15/03/2011 - 00:43:46 | D ] E:\Stupava
[05/03/2013 - 16:42:50 | N | 2479648] E:\20130202_162034.jpg
[05/03/2013 - 16:42:52 | N | 1806259] E:\20130202_162028.jpg
[05/03/2013 - 16:42:52 | N | 3150187] E:\20130202_162003.jpg
[22/03/2011 - 14:03:32 | N | 7912602] E:\eb_jk_zakladna_klasifikacia_a_vznik_zivota_pdf.pdf
[05/03/2013 - 16:42:52 | N | 1849533] E:\20130202_161954.jpg
[05/03/2013 - 16:42:52 | N | 2184583] E:\20130202_161947.jpg
[22/03/2011 - 14:51:46 | N | 9052160] E:\Manual.doc
[25/03/2011 - 14:14:26 | N | 31232] E:\Ratingove agentury.doc
[05/03/2013 - 16:42:54 | N | 2896876] E:\20130202_161935.jpg
[05/03/2013 - 16:42:56 | N | 2185515] E:\20130202_145528.jpg
[26/03/2011 - 23:29:16 | N | 13457] E:\Ciele a kompetencie.doc.docx
[05/03/2013 - 16:43:00 | N | 3175193] E:\20130202_145325.jpg
[05/03/2013 - 16:43:00 | N | 3021035] E:\20130202_144506.jpg
[05/03/2013 - 16:43:00 | N | 3023798] E:\20130202_144450.jpg
[28/03/2011 - 09:44:14 | N | 27648] E:\Ciele a kompetencie.doc
[05/03/2013 - 16:43:02 | N | 3264402] E:\20130202_144444.jpg
[05/03/2013 - 16:43:02 | N | 3025031] E:\20130202_144417.jpg
[05/03/2013 - 16:43:02 | N | 3570817] E:\20130202_125444.jpg
[05/03/2013 - 16:43:02 | N | 3461872] E:\20130202_125451.jpg
[05/03/2013 - 16:43:04 | N | 3542913] E:\20130202_125506.jpg
[05/03/2013 - 16:43:04 | N | 2789546] E:\20130202_193742.jpg
[05/03/2013 - 16:43:06 | N | 3468339] E:\20130202_125437.jpg
[05/03/2013 - 16:43:08 | N | 2304074] E:\20130202_115407.jpg
[05/03/2013 - 16:43:10 | N | 1792383] E:\20130202_115356.jpg
[05/03/2013 - 16:43:14 | N | 1859020] E:\20130202_115347.jpg
[05/03/2013 - 16:43:18 | N | 18612657] E:\20130202_154247.mp4
[05/03/2013 - 16:43:34 | N | 54451094] E:\20130202_145035.mp4
[05/03/2013 - 16:44:00 | N | 62187994] E:\20130202_145150.mp4
[05/03/2013 - 16:44:16 | N | 20565541] E:\20130202_154114.mp4
[05/03/2013 - 16:44:26 | N | 28121218] E:\20130202_154200.mp4
[05/03/2013 - 16:44:28 | N | 2310727] E:\20130201_222902.jpg
[05/03/2013 - 16:44:30 | N | 2898928] E:\20130201_222854.jpg
[05/03/2013 - 16:44:30 | N | 503772] E:\20130201_200136.jpg
[05/03/2013 - 16:44:32 | N | 472596] E:\20130201_200125.jpg
[05/03/2013 - 16:44:32 | N | 3201856] E:\20130201_195941.jpg
[05/03/2013 - 16:44:34 | N | 3186702] E:\20130201_195921.jpg
[05/03/2013 - 16:44:36 | N | 2596296] E:\20130201_195953.jpg
[05/03/2013 - 16:44:36 | N | 2529414] E:\20130201_200101.jpg
[05/03/2013 - 16:44:38 | N | 2881231] E:\20130201_184054.jpg
[05/03/2013 - 16:44:40 | N | 3637574] E:\20130201_184041.jpg
[05/03/2013 - 16:44:42 | N | 14488735] E:\20130201_213351.mp4
[05/03/2013 - 16:44:48 | N | 3353179] E:\20130201_160904.jpg
[05/03/2013 - 16:44:58 | N | 55474414] E:\20130201_213212.mp4
[05/03/2013 - 16:45:20 | N | 56994137] E:\20130201_213249.mp4
[05/03/2013 - 16:45:28 | N | 6825879] E:\20130201_213326.mp4
[05/03/2013 - 16:45:28 | N | 2621983] E:\20130201_160833.jpg
[05/03/2013 - 16:45:32 | N | 3489671] E:\20130201_160824.jpg
[05/03/2013 - 16:45:32 | N | 3839932] E:\20130201_130153.jpg
[05/03/2013 - 16:45:34 | N | 3579835] E:\20130201_130134.jpg
[05/03/2013 - 16:45:36 | N | 3434464] E:\20130201_125917.jpg
[05/03/2013 - 16:45:38 | N | 3613536] E:\20130201_130025.jpg
[05/03/2013 - 16:45:38 | N | 3616435] E:\20130201_125944.jpg
[05/03/2013 - 16:45:40 | N | 3801982] E:\20130201_125933.jpg
[05/03/2013 - 16:45:40 | N | 2263941] E:\20130201_122809.jpg
[05/03/2013 - 16:45:42 | N | 3717523] E:\20130201_125853.jpg
[05/03/2013 - 16:45:44 | N | 3409120] E:\20130201_125912.jpg
[05/03/2013 - 16:45:44 | N | 3617180] E:\20130201_125858.jpg
[05/03/2013 - 16:45:46 | N | 2467931] E:\20130201_122803.jpg
[05/03/2013 - 16:45:46 | N | 3310828] E:\20130201_122757.jpg
[05/03/2013 - 16:46:30 | N | 3776185] E:\20130201_122716.jpg
[05/03/2013 - 16:46:30 | N | 3768207] E:\20130201_122711.jpg
[05/03/2013 - 16:46:32 | N | 2394073] E:\20130201_122224.jpg
[05/03/2013 - 16:46:32 | N | 2335542] E:\20130201_122234.jpg
[05/03/2013 - 16:46:32 | N | 1980971] E:\20130201_122238.jpg
[05/03/2013 - 16:46:32 | N | 2232861] E:\20130201_122249.jpg
[05/03/2013 - 16:46:32 | N | 3653644] E:\20130201_114435.jpg
[05/03/2013 - 16:46:32 | N | 3005292] E:\20130201_114648.jpg
[05/03/2013 - 16:46:34 | N | 2790802] E:\20130201_114657.jpg
[05/03/2013 - 16:46:34 | N | 1866936] E:\20130201_122218.jpg
[05/03/2013 - 16:46:34 | N | 3775631] E:\20130201_113646.jpg
[05/03/2013 - 16:46:46 | N | 47721605] E:\20130201_162906.mp4
[05/03/2013 - 16:47:26 | N | 191022232] E:\20130201_162706.mp4
[05/03/2013 - 16:47:46 | N | 15572223] E:\20130201_133117.mp4
[05/03/2013 - 16:48:02 | N | 75504507] E:\20130201_131653.mp4
[05/03/2013 - 16:48:12 | N | 29447646] E:\20130201_130625.mp4
[05/03/2013 - 16:48:16 | N | 13943562] E:\20130201_114355.mp4
[05/03/2013 - 16:48:16 | N | 486572] E:\20130131_122321.jpg
[05/03/2013 - 16:48:18 | N | 2520222] E:\20130131_122355.jpg
[05/03/2013 - 16:48:18 | N | 2414864] E:\20130131_122402.jpg
[05/03/2013 - 16:48:22 | N | 28655169] E:\20130201_114223.mp4
[05/03/2013 - 16:48:22 | N | 473135] E:\20130131_122312.jpg
[05/03/2013 - 16:48:24 | N | 2654074] E:\20130131_122246.jpg
[05/03/2013 - 16:48:24 | N | 1916355] E:\20130131_122235.jpg
[05/03/2013 - 16:48:24 | N | 2144023] E:\20130131_122227.jpg
[10/03/2013 - 17:13:40 | N | 2710049] E:\20130206_193019.jpg
[05/03/2013 - 16:14:40 | N | 155136] E:\DDS_zakon_05_03_2013.doc
[10/03/2013 - 17:13:40 | N | 2264352] E:\20130206_193014.jpg
[10/03/2013 - 17:13:40 | N | 3655295] E:\20130205_192954.jpg
[10/03/2013 - 17:13:40 | N | 3568454] E:\20130205_192957.jpg
[10/03/2013 - 17:13:42 | N | 3383885] E:\20130205_193338.jpg
[10/03/2013 - 17:13:42 | N | 2718564] E:\20130205_193351.jpg
[10/03/2013 - 17:13:50 | N | 36038391] E:\20130204_232858.mp4
[10/03/2013 - 17:13:50 | N | 3744151] E:\20130204_163700.jpg
[05/03/2013 - 16:40:26 | N | 3618645] E:\20130204_083945.jpg
[10/03/2013 - 17:13:50 | N | 3517478] E:\20130205_192857.jpg
[10/03/2013 - 17:13:52 | N | 3320732] E:\20130205_192915.jpg
[10/03/2013 - 17:13:54 | N | 2360350] E:\20130204_133413.jpg
[10/03/2013 - 17:13:56 | N | 3602120] E:\20130204_163635.jpg
[10/03/2013 - 17:13:56 | N | 3723555] E:\20130204_163628.jpg
[10/03/2013 - 17:13:58 | N | 3811367] E:\20130204_163609.jpg
[10/03/2013 - 17:13:58 | N | 2399430] E:\20130204_133450.jpg
[10/03/2013 - 17:13:58 | N | 3689978] E:\20130204_140228.jpg
[10/03/2013 - 17:14:00 | N | 3542928] E:\20130204_140245.jpg
[10/03/2013 - 17:14:06 | N | 42316116] E:\20130204_114704.mp4
[10/03/2013 - 17:14:08 | N | 3730696] E:\20130204_130023.jpg
[10/03/2013 - 17:14:08 | N | 2911495] E:\20130204_114657.jpg
[10/03/2013 - 17:14:08 | N | 2410528] E:\20130204_114648.jpg
[10/03/2013 - 17:14:10 | N | 2394959] E:\20130204_114646.jpg
[10/03/2013 - 17:14:10 | N | 2952810] E:\20130204_114453.jpg
[10/03/2013 - 17:14:12 | N | 9497592] E:\20130204_114405.mp4
[10/03/2013 - 17:14:16 | N | 2641466] E:\20130204_114440.jpg
[10/03/2013 - 17:14:16 | N | 3063129] E:\20130204_114429.jpg
[10/03/2013 - 17:14:16 | N | 3724440] E:\20130204_084603.jpg
[10/03/2013 - 17:14:16 | N | 3498297] E:\20130204_084629.jpg
[10/03/2013 - 17:14:18 | N | 2915711] E:\20130206_193146.jpg
[12/03/2013 - 20:03:34 | RASHD ] E:\Autorun.inf
[12/03/2013 - 21:12:17 | SHD ] K:\$RECYCLE.BIN
[24/12/2010 - 20:46:30 | N | 173] K:\.SBSettings.xml
[25/08/2010 - 21:42:20 | D ] K:\05 Taupl 2010
[10/09/2010 - 19:02:44 | D ] K:\06 Velka noc 2010
[22/05/2012 - 21:32:27 | D ] K:\07 Bar nar 2010
[22/10/2010 - 20:55:30 | D ] K:\Avatar
[27/05/2011 - 15:51:38 | D ] K:\FullDisc
[27/05/2011 - 17:31:46 | D ] K:\MainMovie
[23/09/2012 - 11:28:07 | D ] K:\MOJE BD A DVD
[10/08/2009 - 14:42:40 | N | 32] K:\start.cmd
[18/10/2010 - 21:34:46 | SHD ] K:\System Volume Information
[22/07/2010 - 00:42:24 | D ] K:\TOSHIBA
[25/08/2010 - 21:52:44 | D ] K:\Turecko 2009
[25/07/2010 - 20:01:37 | D ] K:\Záloha z WD

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
K:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F |

Re: Delta Search

Napsal: 12 bře 2013 21:42
od vyosek
Pockam jeste na OTL

Re: Delta Search

Napsal: 12 bře 2013 22:14
od Huso
OtL ma divny priebeh. Po spusteni Run Fix bezal asi 10 sek, potom akoby sa zasekol, v hornej liste ma vypisane ze nereaguje a takto to je uz minimalne 10min, bezo zmeny, bez ukoncenia, bez logu... Co robit?

Re: Delta Search

Napsal: 12 bře 2013 22:39
od vyosek
Zkuste pouzit tento skript

Kód: Vybrat vše

:otl
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before Last Install)
DRV - File not found [Adapter | On_Demand | Unknown] -- -- (Winsock - Google Desktop Search Backup Before First Install)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pccsmcfd.sys -- (pccsmcfd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dsnpfd.sys -- (dsnpfdMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Peter\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\TBPANEL.SYS -- (Cardex)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.startsearcher.com/?q={searchTerms}&src=IETB
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.delta-search.com/?affID=1195 ... 21855d186e
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-search.com/?affID=1195 ... 21855d186e
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.google.com
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 30 E6 DA 84 E8 18 CD 01 [binary data]
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,BrowserMngrDefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119520&babsrc=SP_ss&mntrId=7a19965c0000000000000021855d186e
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{1D7662A0-5BCA-4052-8EE8-276CD182692A}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7IRFC_sk
FF - prefs.js..browser.search.selectedEngine: "Delta Search"
FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119520&babsrc=HP_ss&mntrId=7a19965c0000000000000021855d186e"¨
[2013/02/27 22:03:15 | 000,006,484 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\a30emazl.default\searchplugins\BrowserProtect.xml
[2013/02/27 22:03:27 | 000,001,294 | ---- | M] () -- C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\a30emazl.default\searchplugins\delta.xml
O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
O3 - HKU\S-1-5-21-2392522767-3960030484-1258025880-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
O33 - MountPoints2\{196bd9c0-c139-11de-832a-0021855d186e}\Shell - "" = AutoRun
[2013/02/27 22:03:26 | 000,000,000 | ---D | C] -- C:\Program Files\Delta
[2013/02/27 22:03:23 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Delta
[4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[5 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[2013/03/02 11:37:06 | 000,000,350 | ---- | M] () -- C:\Windows\Tasks\AddLyrics update.job
[2013/03/02 14:39:28 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/03/02 11:36:54 | 000,000,920 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013/03/02 14:02:00 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013/03/01 15:35:00 | 000,000,894 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004Core.job
[2013/03/02 14:35:15 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004UA.job

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"UpdateLBPShortCut"=-
"MDS_Menu"=-
"CLMLServer"=-
"UpdateP2GoShortCut"=-
"RemoteControl8"=-
"PDVD8LanguageShortcut"=-
"BDRegion"=-
"UpdatePPShortCut"=-
"UCam_Menu"=-
"LGODDFU"=-
"UpdatePSTShortCut"=-
"Adobe ARM"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
"WMPNSCFG"=-
"Skype"=-

:files
C:\Program Files\Delta
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:commands
[RESETHOSTS]
[EMPTYTEMP]

Re: Delta Search

Napsal: 12 bře 2013 22:58
od Huso
Skusil som. Akonahle pride k Processing O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82...... zasekne sa, nereaguje a stoji. Cakal som dalsich 10 min, ziadna zmena... Pomoze, ked poslem aktualny log z RSIT?

Re: Delta Search

Napsal: 12 bře 2013 23:02
od vyosek
OK, dejte novy log z RSIT

Re: Delta Search

Napsal: 12 bře 2013 23:10
od Huso
Logfile of random's system information tool 1.09 (written by random/random)
Run by Peter at 2013-03-12 23:07:59
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 4 GB (1%) free of 477 GB
Total RAM: 3070 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:08:57, on 12. 3. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gAutoPan.exe
C:\Genius\ioCentre\gAutoScroll.exe
C:\Genius\ioCentre\gZoom.exe
C:\Genius\ioCentre\gIMMgm.exe
C:\Genius\ioCentre\gKbStatus.exe
C:\Genius\ioCentre\gDeskMgm.exe
C:\Genius\ioCentre\gTaskSwitch.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Users\Peter\Desktop\RSIT.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\trend micro\Peter.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: LyricsTube - {B399EDE8-1525-458C-8DD9-31EADF632D06} - C:\Program Files\LyricsTube\lrcstube.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\Windows\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11 SE DVD\uvPL.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [MDS_Menu] "C:\Program Files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\MediaShow4" UpdateWithCreateOnce "Software\CyberLink\MediaShow\4.1"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: _uninst_33367102.lnk = C:\Users\Peter\AppData\Local\Temp\_uninst_33367102.bat
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - https://moja.tatrabanka.sk/ibanking/ICApki.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 11553 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004UA.job
C:\Windows\tasks\LyricsTube Update.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\a30emazl.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "{093797b3-38e9-4f7f-a525-4d1bd97f68b6}:1.0, linkfilter@kaspersky.ru:9.0.0.463, onair_FM@marek.chrenko.net:3.5.1, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"url_advisor@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\url_advisor@kaspersky.com
"virtual_keyboard@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\virtual_keyboard@kaspersky.com
"content_blocker@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\content_blocker@kaspersky.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.171 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
linkfilter@kaspersky.ru
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
GoogleDesktopMozilla.dll
GoogleDesktopMozillaStub.js
GoogleDesktopMozillaStub.xpt

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
toolkitsearch.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\a30emazl.default\extensions\
plugin@startsearcher.com
plugin@videofiledownload.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17 537528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-17 811960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-07-05 4018888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B399EDE8-1525-458C-8DD9-31EADF632D06}]
LyricsTube - C:\Program Files\LyricsTube\lrcstube.dll [2013-03-03 109568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17 484280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-07-03 6266880]
"PinnacleDriverCheck"=C:\Windows\system32\PSDrvCheck.exe [2004-03-10 406016]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"UVS11 Preload"=C:\Program Files\Ulead Systems\Ulead VideoStudio 11 SE DVD\uvPL.exe [2007-04-12 341488]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2007-12-17 61440]
"NeroFilterCheck"=C:\Windows\system32\NeroCheck.exe [2001-07-09 155648]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"MDS_Menu"=C:\Program Files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe [2009-02-25 218408]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2009-06-03 103720]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2009-07-16 91432]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2009-04-15 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared files\brs.exe [2010-04-02 75048]
"UpdatePPShortCut"=C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2009-02-17 218408]
"LGODDFU"=C:\Program Files\lg_fwupdate\fwupdate.exe [2010-02-15 557056]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe [2009-09-30 210216]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
"NetWorx"=C:\Program Files\NetWorx\networx.exe [2012-01-15 3309568]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [2012-11-15 356376]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-11-28 59280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Google Update"=C:\Users\Peter\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-18 136176]
"SkyDrive"=C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2012-11-16 255992]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2013-01-08 18705664]

C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
_uninst_33367102.lnk - C:\Users\Peter\AppData\Local\Temp\_uninst_33367102.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=vdrcodec.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.PIM1"=pclepim1.dll
"msacm.dvacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.avis"=ff_acm.acm
"vidc.mjpg"=pvmjpg30.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-03-12 23:04:10 ----ASH---- C:\hiberfil.sys
2013-03-12 21:20:18 ----D---- C:\_OTL
2013-03-12 21:13:02 ----RASHD---- C:\Autorun.inf
2013-03-12 20:13:03 ----A---- C:\Windows\ntbtlog.txt
2013-03-12 19:48:06 ----A---- C:\UsbFix.txt
2013-03-12 19:48:04 ----D---- C:\UsbFix
2013-03-11 06:20:13 ----D---- C:\rsit
2013-03-10 21:27:31 ----A---- C:\Windows\system32\drivers\5499943drv.sys
2013-03-10 20:57:08 -------- C:\AdwCleaner[S3].txt
2013-03-10 20:54:35 -------- C:\AdwCleaner[R3].txt
2013-03-10 14:03:14 ----D---- C:\ProgramData\Ꮘʢㅐʌ
2013-03-10 13:43:02 ----A---- C:\Windows\system32\drivers\7833001drv.sys
2013-03-10 13:10:57 ----D---- C:\ProgramData\䇘8㺈80
2013-03-10 11:26:02 ----D---- C:\ProgramData\䇘Ǭ㺈Ǭ0
2013-03-05 16:11:19 ----A---- C:\Windows\system32\drivers\SET7C40.tmp
2013-03-05 16:09:58 ----D---- C:\ProgramData\䇘Ƥ㺈Ƥ0
2013-03-05 16:09:48 ----D---- C:\Program Files\LyricsTube
2013-03-05 15:57:45 ----D---- C:\Windows\system32\Extensions
2013-03-03 18:15:32 ----A---- C:\Windows\system32\WNASPI32.DLL
2013-03-03 18:15:32 ----A---- C:\Windows\system32\drivers\ASPI32.SYS
2013-03-03 18:15:24 ----D---- C:\Program Files\4Musics FLAC to MP3 Converter
2013-03-03 11:04:51 ----A---- C:\Windows\system32\drivers\33367102.sys
2013-03-02 11:37:42 ----D---- C:\ProgramData\䇘[㺈[0
2013-03-02 11:31:36 -------- C:\AdwCleaner[S2].txt
2013-03-02 09:29:01 ----D---- C:\ProgramData\䇘(㺈(0
2013-03-02 08:58:33 -------- C:\log AdwCleaner 02032013.txt
2013-03-02 08:53:15 -------- C:\AdwCleaner[R2].txt
2013-03-01 17:08:22 ----D---- C:\ProgramData\Ꮘʱㅐˊ
2013-03-01 16:51:33 ----D---- C:\ProgramData\䇘Ÿ㺈Ÿ0
2013-03-01 12:12:38 ----D---- C:\ProgramData\䇘ǣ㺈ǣ0
2013-02-27 22:50:28 ----D---- C:\ProgramData\䇘í㺈í0
2013-02-27 22:00:42 ----D---- C:\Program Files\AddLyrics
2013-02-27 22:00:33 ----D---- C:\Program Files\Media converter
2013-02-27 07:40:18 ----D---- C:\Program Files\Mozilla Firefox
2013-02-13 06:58:45 ----D---- C:\Program Files\Common Files\Skype
2013-02-13 03:07:46 ----A---- C:\Windows\system32\vbscript.dll
2013-02-13 03:07:46 ----A---- C:\Windows\system32\mshtmled.dll
2013-02-13 03:07:45 ----A---- C:\Windows\system32\msfeeds.dll
2013-02-13 03:07:45 ----A---- C:\Windows\system32\jsproxy.dll
2013-02-13 03:07:45 ----A---- C:\Windows\system32\ieUnatt.exe
2013-02-13 03:07:45 ----A---- C:\Windows\system32\ieui.dll
2013-02-13 03:07:44 ----A---- C:\Windows\system32\wininet.dll
2013-02-13 03:07:44 ----A---- C:\Windows\system32\jscript.dll
2013-02-13 03:07:43 ----A---- C:\Windows\system32\url.dll
2013-02-13 03:07:43 ----A---- C:\Windows\system32\jscript9.dll
2013-02-13 03:07:43 ----A---- C:\Windows\system32\iertutil.dll
2013-02-13 03:07:42 ----A---- C:\Windows\system32\urlmon.dll
2013-02-13 03:07:41 ----A---- C:\Windows\system32\mshtml.dll
2013-02-13 03:07:39 ----A---- C:\Windows\system32\ieframe.dll

======List of files/folders modified in the last 1 month======

2013-03-12 23:08:17 ----D---- C:\Windows\Temp
2013-03-12 23:08:10 ----D---- C:\Program Files\trend micro
2013-03-12 23:07:30 ----D---- C:\Users\Peter\AppData\Roaming\Skype
2013-03-12 23:07:09 ----D---- C:\ProgramData\Kaspersky Lab
2013-03-12 23:06:19 ----D---- C:\Users\Peter\AppData\Roaming\OpenOffice.org2
2013-03-12 22:49:43 ----D---- C:\Windows\System32
2013-03-12 22:49:43 ----D---- C:\Windows\inf
2013-03-12 22:49:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-03-12 22:43:40 ----D---- C:\Windows\Prefetch
2013-03-12 21:12:17 ----SHD---- C:\$Recycle.Bin
2013-03-12 20:57:11 ----D---- C:\Users\Peter\AppData\Roaming\vlc
2013-03-12 20:13:03 ----D---- C:\Windows
2013-03-12 19:59:44 ----SHD---- C:\System Volume Information
2013-03-12 08:04:18 ----D---- C:\Windows\Minidump
2013-03-11 05:37:05 ----D---- C:\Windows\system32\drivers\etc
2013-03-10 21:27:34 ----D---- C:\Windows\system32\drivers
2013-03-10 14:25:53 ----HD---- C:\ProgramData
2013-03-10 14:16:04 ----D---- C:\Program Files
2013-03-10 14:01:32 ----D---- C:\Windows\system32\Tasks
2013-03-10 13:57:09 ----SD---- C:\Users\Peter\AppData\Roaming\Microsoft
2013-03-10 13:08:57 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-10 11:35:48 ----SHD---- C:\Windows\Installer
2013-03-10 11:35:47 ----D---- C:\Config.Msi
2013-03-10 11:35:46 ----D---- C:\Users\Peter\AppData\Roaming\Mozilla
2013-03-05 16:09:48 ----D---- C:\Windows\Tasks
2013-03-03 20:20:38 ----D---- C:\Users\Peter\AppData\Roaming\dvdcss
2013-03-03 10:21:53 ----D---- C:\Users\Peter\AppData\Roaming\uTorrent
2013-03-03 10:20:57 ----D---- C:\Windows\Debug
2013-03-02 11:39:51 ----D---- C:\Users\Peter\AppData\Roaming\Dropbox
2013-03-02 04:04:44 ----D---- C:\Program Files\Google
2013-03-01 17:08:02 ----D---- C:\Windows\system32\catroot2
2013-02-27 23:33:12 ----D---- C:\audiograbber
2013-02-27 22:06:19 ----D---- C:\Windows\system32\config
2013-02-27 22:01:42 ----RSD---- C:\Windows\assembly
2013-02-27 21:39:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-02-19 18:13:29 ----D---- C:\Users\Peter\AppData\Roaming\Audacity
2013-02-13 06:58:58 ----D---- C:\ProgramData\Skype
2013-02-13 06:58:45 ----RD---- C:\Program Files\Skype
2013-02-13 06:58:45 ----D---- C:\Program Files\Common Files
2013-02-13 03:45:45 ----D---- C:\Windows\Microsoft.NET
2013-02-13 03:34:44 ----D---- C:\Windows\system32\migration
2013-02-13 03:34:44 ----D---- C:\Program Files\Internet Explorer
2013-02-13 03:11:48 ----A---- C:\Windows\system32\mrt.exe
2013-02-13 03:10:22 ----D---- C:\ProgramData\Microsoft Help
2013-02-13 03:09:33 ----D---- C:\Windows\winsxs
2013-02-13 03:08:26 ----D---- C:\Windows\system32\catroot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 33367102;33367102; C:\Windows\system32\DRIVERS\33367102.sys [2013-03-03 133208]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2012-06-19 136024]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2008-06-16 44944]
R1 7833001drv;7833001drv; C:\Windows\system32\DRIVERS\7833001drv.sys [2013-03-03 489048]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2012-11-15 589144]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2012-08-02 24408]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2012-11-15 43608]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2012-08-13 144344]
R1 networx;networx; C:\Windows\system32\drivers\networx.sys [2011-04-15 51640]
R1 PCLEPCI;PCLEPCI; \??\C:\Windows\system32\drivers\pclepci.sys [2004-07-16 14165]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2010/02/15 11:29:08]; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [2010-01-12 87536]
R3 ASAPIW2k;ASAPIW2K; C:\Windows\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2009-04-28 19456]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2009-03-04 11520]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2012-10-25 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2012-10-25 25944]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 30576]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-10-10 10837352]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-12-27 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-02-14 118784]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S1 5499943drv;5499943drv; C:\Windows\system32\DRIVERS\5499943drv.sys [2013-03-10 489048]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2008-01-19 45696]
S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\Windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
S3 Avc;AVC Device; C:\Windows\system32\DRIVERS\avc.sys [2008-01-19 40448]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\Windows\system32\DRIVERS\avcstrm.sys [2008-01-19 14208]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 INIDVD;Initio USB DVD Filter Driver; C:\Windows\system32\DRIVERS\inidvd.sys [2008-09-24 15640]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-07-03 2152088]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-19 52608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\Windows\system32\DRIVERS\mstape.sys [2008-01-19 50048]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader; C:\Windows\system32\DRIVERS\SCR33X2K.sys [2004-04-06 64088]
S3 SCR3XX2K;SCR3xx USB SmartCardReader; C:\Windows\system32\DRIVERS\SCR3XX2K.sys [2009-10-25 57600]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-07-07 23600]
S3 USBCCID;USB Smart Card reader; C:\Windows\system32\DRIVERS\usbccid.sys [2009-04-11 30208]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8; C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [2012-11-15 356376]
R2 BcmSqlStartupSvc;Spúšacia služba produktu Business Contact Manager SQL Server; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2009-02-23 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-12-13 135536]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 645992]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2009-07-02 244904]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-21 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-10-07 867080]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-21 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-10 115608]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]

-----------------EOF-----------------

Re: Delta Search

Napsal: 13 bře 2013 08:52
od vyosek
Aplikujte jets tento skript pro OTL

Kód: Vybrat vše

:otl
[2013/02/27 22:03:26 | 000,000,000 | ---D | C] -- C:\Program Files\Delta
[2013/02/27 22:03:23 | 000,000,000 | ---D | C] -- C:\Users\Peter\AppData\Roaming\Delta
[4 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[5 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[2013/03/02 11:37:06 | 000,000,350 | ---- | M] () -- C:\Windows\Tasks\AddLyrics update.job
[2013/03/02 14:39:28 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013/03/02 11:36:54 | 000,000,920 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013/03/02 14:02:00 | 000,000,924 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013/03/01 15:35:00 | 000,000,894 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004Core.job
[2013/03/02 14:35:15 | 000,000,946 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004UA.job

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=-
"UpdateLBPShortCut"=-
"MDS_Menu"=-
"CLMLServer"=-
"UpdateP2GoShortCut"=-
"RemoteControl8"=-
"PDVD8LanguageShortcut"=-
"BDRegion"=-
"UpdatePPShortCut"=-
"UCam_Menu"=-
"LGODDFU"=-
"UpdatePSTShortCut"=-
"Adobe ARM"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
"WMPNSCFG"=-
"Skype"=-

:files
C:\Program Files\Delta
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp

:commands
[RESETHOSTS]
[EMPTYTEMP]

Re: Delta Search

Napsal: 13 bře 2013 12:15
od Huso
Aplikoval som, log prikladam, vyzera to tak, ze Delty sme sa zbavili.
Problemom ale ostava, ze aj teraz po restarte ked prebehol OTL , znovu blikol modry monitor, vyzyva ma na "insert Windows instalation disk and repair computer"... znovu som to rozbehol len cez safe mode a nasledny restart v safe mode...:shock:

All processes killed
========== OTL ==========
Folder C:\Program Files\Delta\ not found.
Folder C:\Users\Peter\AppData\Roaming\Delta\ not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP32D2.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP421E.tmp\Microsoft.Interop.eCRM.msforms.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP421E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8D19.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD5C5.tmp folder deleted successfully.
C:\Windows\Installer\MSI709A.tmp- folder deleted successfully.
C:\Windows\Installer\MSIB59C.tmp deleted successfully.
C:\Windows\Installer\MSIBF86.tmp- folder deleted successfully.
C:\Windows\Installer\MSICCF8.tmp deleted successfully.
C:\Windows\Installer\MSIEBD6.tmp- folder deleted successfully.
File C:\Windows\Tasks\AddLyrics update.job not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004Core.job moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2392522767-3960030484-1258025880-1004UA.job moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateLBPShortCut deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MDS_Menu deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CLMLServer deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GoShortCut deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RemoteControl8 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PDVD8LanguageShortcut deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\BDRegion deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdatePPShortCut deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UCam_Menu deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LGODDFU deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UpdatePSTShortCut deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
========== FILES ==========
File\Folder C:\Program Files\Delta not found.
File/Folder C:\Windows\system32\*.tmp.dll not found.
C:\Windows\system32\drivers\SET7C40.tmp moved successfully.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Peter
->Temp folder emptied: 27034966 bytes
->Temporary Internet Files folder emptied: 332896 bytes
->FireFox cache emptied: 34872636 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1877 bytes

User: Public

User: USER
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 50808 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 59,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03132013_115823

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Delta Search

Napsal: 13 bře 2013 12:59
od vyosek
:arrow: No, to vypada bud na naboreny system\soubory nebo registr

:arrow: Mate nekde instalacni CD, abychom je opravili :???:

Re: Delta Search

Napsal: 13 bře 2013 14:49
od Huso
Comp som kupoval s nainstalovanym systemom priamo od predajcu, Produkt key je nalepeny priamo na PC, Instalacne CD nemam, nebude zalohovane niekde na HDD?.. :oops:

Re: Delta Search

Napsal: 13 bře 2013 21:38
od Huso
Prikladam este aktualny log z RSIT.
Primarny problem Delta Search je, zda sa, vyrieseny.
Ten novy, s opakujucim sa BSOD pri starte systemu budeme riesit tu, alebo mam zalozit nove vlakno v prislusnej teme?? :?:
V kazdom pripade vdaka za doterajsiu pomoc!!


Logfile of random's system information tool 1.09 (written by random/random)
Run by Peter at 2013-03-13 21:25:55
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 1 GB (0%) free of 477 GB
Total RAM: 3070 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:26:43, on 13. 3. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16470)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\NetWorx\networx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gAutoPan.exe
C:\Genius\ioCentre\gAutoScroll.exe
C:\Genius\ioCentre\gZoom.exe
C:\Windows\ehome\ehmsas.exe
C:\Genius\ioCentre\gIMMgm.exe
C:\Genius\ioCentre\gKbStatus.exe
C:\Windows\System32\mobsync.exe
C:\Genius\ioCentre\gDeskMgm.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Genius\ioCentre\gTaskSwitch.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
C:\Windows\system32\Taskmgr.exe
C:\Users\Peter\Desktop\RSIT.exe
C:\Program Files\trend micro\Peter.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: LyricsTube - {B399EDE8-1525-458C-8DD9-31EADF632D06} - C:\Program Files\LyricsTube\lrcstube.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\Windows\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11 SE DVD\uvPL.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: _uninst_33367102.lnk = C:\Users\Peter\AppData\Local\Temp\_uninst_33367102.bat
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - https://moja.tatrabanka.sk/ibanking/ICApki.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Služba Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 9518 bytes

======Scheduled tasks folder======

C:\Windows\tasks\LyricsTube Update.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\a30emazl.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.google.sk/"
prefs.js - "extensions.enabledItems" - "{093797b3-38e9-4f7f-a525-4d1bd97f68b6}:1.0, linkfilter@kaspersky.ru:9.0.0.463, onair_FM@marek.chrenko.net:3.5.1, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.4.51, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"url_advisor@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\url_advisor@kaspersky.com
"virtual_keyboard@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\virtual_keyboard@kaspersky.com
"content_blocker@kaspersky.com"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\FFExt\content_blocker@kaspersky.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.171 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_171.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
linkfilter@kaspersky.ru
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
GoogleDesktopMozilla.dll
GoogleDesktopMozillaStub.js
GoogleDesktopMozillaStub.xpt

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
toolkitsearch.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\a30emazl.default\extensions\
plugin@startsearcher.com
plugin@videofiledownload.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17 537528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-17 811960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-07-05 4018888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B399EDE8-1525-458C-8DD9-31EADF632D06}]
LyricsTube - C:\Program Files\LyricsTube\lrcstube.dll [2013-03-03 109568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17 484280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-07-03 6266880]
"PinnacleDriverCheck"=C:\Windows\system32\PSDrvCheck.exe [2004-03-10 406016]
"USBToolTip"=C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [2007-02-20 199752]
"UVS11 Preload"=C:\Program Files\Ulead Systems\Ulead VideoStudio 11 SE DVD\uvPL.exe [2007-04-12 341488]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2007-12-17 61440]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-09-04 767312]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
"NetWorx"=C:\Program Files\NetWorx\networx.exe [2012-01-15 3309568]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [2012-11-15 356376]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-11-28 59280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"WindowsWelcomeCenter"=oobefldr.dll,ShowWelcomeCenter []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"SkyDrive"=C:\Users\Peter\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2012-11-16 255992]

C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
_uninst_33367102.lnk - C:\Users\Peter\AppData\Local\Temp\_uninst_33367102.bat

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=vdrcodec.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"vidc.XVID"=xvidvfw.dll
"VIDC.PIM1"=pclepim1.dll
"msacm.dvacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.avis"=ff_acm.acm
"vidc.mjpg"=pvmjpg30.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-03-13 20:54:49 ----D---- C:\Users\Peter\AppData\Roaming\JAM Software
2013-03-13 20:54:45 ----D---- C:\Program Files\JAM Software
2013-03-13 20:50:12 ----D---- C:\Program Files\CPUID
2013-03-13 20:07:36 ----ASH---- C:\hiberfil.sys
2013-03-13 03:00:35 ----A---- C:\Windows\system32\vbscript.dll
2013-03-13 03:00:35 ----A---- C:\Windows\system32\mshtmled.dll
2013-03-13 03:00:34 ----A---- C:\Windows\system32\wininet.dll
2013-03-13 03:00:34 ----A---- C:\Windows\system32\msfeeds.dll
2013-03-13 03:00:34 ----A---- C:\Windows\system32\jsproxy.dll
2013-03-13 03:00:34 ----A---- C:\Windows\system32\jscript.dll
2013-03-13 03:00:34 ----A---- C:\Windows\system32\ieUnatt.exe
2013-03-13 03:00:34 ----A---- C:\Windows\system32\ieui.dll
2013-03-13 03:00:33 ----A---- C:\Windows\system32\urlmon.dll
2013-03-13 03:00:33 ----A---- C:\Windows\system32\url.dll
2013-03-13 03:00:33 ----A---- C:\Windows\system32\jscript9.dll
2013-03-13 03:00:33 ----A---- C:\Windows\system32\iertutil.dll
2013-03-13 03:00:32 ----A---- C:\Windows\system32\mshtml.dll
2013-03-13 03:00:32 ----A---- C:\Windows\system32\ieframe.dll
2013-03-12 21:20:18 ----D---- C:\_OTL
2013-03-12 21:13:02 ----RASHD---- C:\Autorun.inf
2013-03-12 20:13:03 ----A---- C:\Windows\ntbtlog.txt
2013-03-12 19:48:06 ----A---- C:\UsbFix.txt
2013-03-12 19:48:04 ----D---- C:\UsbFix
2013-03-11 06:20:13 ----D---- C:\rsit
2013-03-10 21:27:31 ----A---- C:\Windows\system32\drivers\5499943drv.sys
2013-03-10 20:57:08 -------- C:\AdwCleaner[S3].txt
2013-03-10 20:54:35 -------- C:\AdwCleaner[R3].txt
2013-03-10 14:03:14 ----D---- C:\ProgramData\Ꮘʢㅐʌ
2013-03-10 13:43:02 ----A---- C:\Windows\system32\drivers\7833001drv.sys
2013-03-10 13:10:57 ----D---- C:\ProgramData\䇘8㺈80
2013-03-10 11:26:02 ----D---- C:\ProgramData\䇘Ǭ㺈Ǭ0
2013-03-05 16:09:58 ----D---- C:\ProgramData\䇘Ƥ㺈Ƥ0
2013-03-05 16:09:48 ----D---- C:\Program Files\LyricsTube
2013-03-05 15:57:45 ----D---- C:\Windows\system32\Extensions
2013-03-03 18:15:32 ----A---- C:\Windows\system32\WNASPI32.DLL
2013-03-03 18:15:32 ----A---- C:\Windows\system32\drivers\ASPI32.SYS
2013-03-03 18:15:24 ----D---- C:\Program Files\4Musics FLAC to MP3 Converter
2013-03-03 11:04:51 ----A---- C:\Windows\system32\drivers\33367102.sys
2013-03-02 11:37:42 ----D---- C:\ProgramData\䇘[㺈[0
2013-03-02 11:31:36 -------- C:\AdwCleaner[S2].txt
2013-03-02 09:29:01 ----D---- C:\ProgramData\䇘(㺈(0
2013-03-02 08:58:33 -------- C:\log AdwCleaner 02032013.txt
2013-03-02 08:53:15 -------- C:\AdwCleaner[R2].txt
2013-03-01 17:08:22 ----D---- C:\ProgramData\Ꮘʱㅐˊ
2013-03-01 16:51:33 ----D---- C:\ProgramData\䇘Ÿ㺈Ÿ0
2013-03-01 12:12:38 ----D---- C:\ProgramData\䇘ǣ㺈ǣ0
2013-02-27 22:50:28 ----D---- C:\ProgramData\䇘í㺈í0
2013-02-27 22:00:42 ----D---- C:\Program Files\AddLyrics
2013-02-27 22:00:33 ----D---- C:\Program Files\Media converter
2013-02-27 07:40:18 ----D---- C:\Program Files\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2013-03-13 21:26:09 ----D---- C:\Windows\Prefetch
2013-03-13 21:26:03 ----D---- C:\Windows\Temp
2013-03-13 21:25:59 ----D---- C:\Program Files\trend micro
2013-03-13 20:54:45 ----D---- C:\Program Files
2013-03-13 20:27:15 ----D---- C:\ProgramData\Kaspersky Lab
2013-03-13 20:13:30 ----D---- C:\Windows\System32
2013-03-13 20:13:30 ----D---- C:\Windows\inf
2013-03-13 20:13:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-03-13 20:09:08 ----D---- C:\Users\Peter\AppData\Roaming\OpenOffice.org2
2013-03-13 19:29:30 ----D---- C:\Users\Peter\AppData\Roaming\Skype
2013-03-13 12:05:24 ----D---- C:\Windows\Minidump
2013-03-13 12:02:49 ----D---- C:\Windows
2013-03-13 11:58:32 ----D---- C:\Windows\system32\drivers\etc
2013-03-13 11:58:31 ----D---- C:\Windows\system32\drivers
2013-03-13 11:58:26 ----SHD---- C:\Windows\Installer
2013-03-13 11:58:26 ----D---- C:\Windows\Tasks
2013-03-13 03:20:39 ----D---- C:\Windows\system32\migration
2013-03-13 03:20:37 ----D---- C:\Program Files\Internet Explorer
2013-03-13 03:02:57 ----D---- C:\Windows\Debug
2013-03-13 03:02:55 ----A---- C:\Windows\system32\mrt.exe
2013-03-13 03:02:37 ----D---- C:\Config.Msi
2013-03-13 03:02:24 ----D---- C:\ProgramData\Microsoft Help
2013-03-13 03:01:35 ----D---- C:\Windows\winsxs
2013-03-13 03:01:22 ----D---- C:\Windows\system32\catroot
2013-03-13 03:01:20 ----D---- C:\Windows\system32\catroot2
2013-03-13 03:00:26 ----SHD---- C:\System Volume Information
2013-03-12 21:12:17 ----SHD---- C:\$Recycle.Bin
2013-03-12 20:57:11 ----D---- C:\Users\Peter\AppData\Roaming\vlc
2013-03-10 14:25:53 ----HD---- C:\ProgramData
2013-03-10 14:01:32 ----D---- C:\Windows\system32\Tasks
2013-03-10 13:57:09 ----SD---- C:\Users\Peter\AppData\Roaming\Microsoft
2013-03-10 13:08:57 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-10 11:35:46 ----D---- C:\Users\Peter\AppData\Roaming\Mozilla
2013-03-03 20:20:38 ----D---- C:\Users\Peter\AppData\Roaming\dvdcss
2013-03-03 10:21:53 ----D---- C:\Users\Peter\AppData\Roaming\uTorrent
2013-03-02 11:39:51 ----D---- C:\Users\Peter\AppData\Roaming\Dropbox
2013-03-02 04:04:44 ----D---- C:\Program Files\Google
2013-02-27 23:33:12 ----D---- C:\audiograbber
2013-02-27 22:06:19 ----D---- C:\Windows\system32\config
2013-02-27 22:01:42 ----RSD---- C:\Windows\assembly
2013-02-27 21:39:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-02-19 18:13:29 ----D---- C:\Users\Peter\AppData\Roaming\Audacity

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 33367102;33367102; C:\Windows\system32\DRIVERS\33367102.sys [2013-03-03 133208]
R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2012-06-19 136024]
R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2008-06-16 44944]
R1 7833001drv;7833001drv; C:\Windows\system32\DRIVERS\7833001drv.sys [2013-03-03 489048]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2012-11-15 589144]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2012-08-02 24408]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2012-11-15 43608]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2012-08-13 144344]
R1 networx;networx; C:\Windows\system32\drivers\networx.sys [2011-04-15 51640]
R1 PCLEPCI;PCLEPCI; \??\C:\Windows\system32\drivers\pclepci.sys [2004-07-16 14165]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2010/02/15 11:29:08]; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [2010-01-12 87536]
R3 ASAPIW2k;ASAPIW2K; C:\Windows\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 gHidPnp;USB Device Enhanced Function Driver; C:\Windows\System32\Drivers\gHidPnp.Sys [2009-04-28 19456]
R3 gMouUsb;USB Mouse Device Drv; C:\Windows\system32\DRIVERS\gMouUsb.sys [2009-03-04 11520]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2012-10-25 25944]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2012-10-25 25944]
R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 30576]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2012-10-10 10837352]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-12-27 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-02-14 118784]
R3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]
S1 5499943drv;5499943drv; C:\Windows\system32\DRIVERS\5499943drv.sys [2013-03-10 489048]
S3 61883;61883 Unit Device; C:\Windows\system32\DRIVERS\61883.sys [2008-01-19 45696]
S3 ASPI;Advanced SCSI Programming Interface Driver; \??\C:\Windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
S3 Avc;AVC Device; C:\Windows\system32\DRIVERS\avc.sys [2008-01-19 40448]
S3 AVCSTRM;AVC Streaming Filter Driver; C:\Windows\system32\DRIVERS\avcstrm.sys [2008-01-19 14208]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 INIDVD;Initio USB DVD Filter Driver; C:\Windows\system32\DRIVERS\inidvd.sys [2008-09-24 15640]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-07-03 2152088]
S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-19 52608]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTAPE;Microsoft AV/C Tape Subunit Device; C:\Windows\system32\DRIVERS\mstape.sys [2008-01-19 50048]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader; C:\Windows\system32\DRIVERS\SCR33X2K.sys [2004-04-06 64088]
S3 SCR3XX2K;SCR3xx USB SmartCardReader; C:\Windows\system32\DRIVERS\SCR3XX2K.sys [2009-10-25 57600]
S3 TVICHW32;TVICHW32; \??\C:\Windows\system32\DRIVERS\TVICHW32.SYS [2009-07-07 23600]
S3 USBCCID;USB Smart Card reader; C:\Windows\system32\DRIVERS\usbccid.sys [2009-04-11 30208]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8; C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184]
R2 AVP;Služba Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe [2012-11-15 356376]
R2 BcmSqlStartupSvc;Spúšacia služba produktu Business Contact Manager SQL Server; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2009-02-23 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-12-13 135536]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 645992]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2009-07-02 244904]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-21 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-10-07 867080]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-21 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-10 115608]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]

-----------------EOF-----------------

Re: Delta Search

Napsal: 13 bře 2013 21:46
od vyosek
:arrow: Start - spustit - napsat cmd - OK - spusti se prikazovy radek - tam napiste sfc /scannow - enter - restart a probehne kontrola

:arrow: Uvidime ci nam to nejak pomuze a dle toho pak uvidime

Re: Delta Search

Napsal: 13 bře 2013 22:28
od Huso
Neda sa spustit, pise mi ze musim byt administrator, aby som mohol pouzit sfc utility. Problem je, ze sa neviem prihlasit ako administrator....