Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Kontrola logu

#1 Příspěvek od Guardian23 »

Dobrý den,

přijde mi, že počítač docela pomalu najíždí. Je pravda, že dlouho neprošel reinstalací. Ale po nalezení tohoto webu mě napadlo, jesti nemůže PC obsahovat malware apod.

Je-li to možné, prosím o kontrolu logu. Předem děkuji.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-11-30 09:00:38
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (6%) free of 50 GB
Total RAM: 2047 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:00:43, on 30.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Firebird\bin\fbserver.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\LiveZilla\LiveZilla.exe
D:\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QIP\qip.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator.LENKA\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [RelevantKnowledge] C:\program files\relevantknowledge\rlvknlg.exe -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [netmon.exe] C:\Program Files\netmon\netmon.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [LiveZilla] "C:\Program Files\LiveZilla\LiveZilla.exe" -minimize
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [systemz] C:\WINDOWS\system32\drivers\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi ... p=ZJfox000
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/63.27/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0379200234
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - D:\nydecky.cz\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Služba inteligentního přenosu na pozadí (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KoopPdfService - Unknown owner - C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: MySQL - MySQL AB - D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Automatické aktualizace (wuauserv) - Unknown owner - C:\WINDOWS\
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.LEN/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 15946 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-484763869-1482476501-725345543-500Core1cb6cbda6e52066.job
C:\WINDOWS\tasks\Install.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IcePick_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_rundll32_exe.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}]
MyWebSearch Search Assistant BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL [2009-08-09 65536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}]
mwsBar BHO - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2009-08-09 438367]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-10-24 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - C:\Program Files\Search Settings\SearchSettings.dll [2009-12-16 1109504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{07B18EA9-A523-4961-B6BB-170DE4475CCA} - My Web Search - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL [2009-08-09 438367]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - Dealio Toolbar - C:\Program Files\Dealio Toolbar\IE\4.0.2\dealioToolbarIE.dll [2009-12-16 700416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"GBB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe [2006-07-12 356352]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-17 148888]
"MyWebSearch Plugin"=rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF []
"My Web Search Bar Search Scope Monitor"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe [2009-08-09 24688]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe [2009-08-09 32838]
"RelevantKnowledge"=C:\program files\relevantknowledge\rlvknlg.exe -boot []
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824]
"netmon.exe"=C:\Program Files\netmon\netmon.exe []
"SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2009-12-16 975360]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-03-16 47392]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-03-17 421888]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-03-12 119152]
"LiveZilla"=C:\Program Files\LiveZilla\LiveZilla.exe [2010-05-17 2651576]
"iTunesHelper"=D:\iTunes\iTunesHelper.exe [2010-07-21 141608]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-10-24 202256]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]
"systemz"=C:\WINDOWS\system32\drivers\ctfmon.exe []
"Google Update"=C:\Documents and Settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
"MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe [2009-08-09 32838]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"QIP2005"=C:\Program Files\QIP\qip.exe [2008-12-09 3259392]

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Administrator.LENKA\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\GOOGLE\GOOGLE~3\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2009-07-20 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"E:\Hry\STALKER\bin\xrEngine.exe"="E:\Hry\STALKER\bin\xrEngine.exe:*:Enabled:Ń.Ň.Ŕ.Ë.Ę.Ĺ.Đ. - ×čńňîĺ Íĺáî (CLI)"
"E:\Hry\STALKER\bin\dedicated\xrEngine.exe"="E:\Hry\STALKER\bin\dedicated\xrEngine.exe:*:Enabled:Ń.Ň.Ŕ.Ë.Ę.Ĺ.Đ. - ×čńňîĺ Íĺáî (SRV)"
"C:\Program Files\bwin\StartbwinPoker.exe"="C:\Program Files\bwin\StartbwinPoker.exe:*:Enabled:StartbwinPoker.exe"
"D:\hl22\HALF LIFE 2\hl2.exe"="D:\hl22\HALF LIFE 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"c:\program files\relevantknowledge\rlvknlg.exe"="c:\program files\relevantknowledge\rlvknlg.exe:*:Enabled:rlvknlg.exe"
"E:\Hry\zh\game.dat"="E:\Hry\zh\game.dat:*:Enabled:game"
"G:\Crack\FlexLM\adskflex.exe"="G:\Crack\FlexLM\adskflex.exe:*:Enabled:adskflex"
"G:\Crack\FlexLM\lmgrd.exe"="G:\Crack\FlexLM\lmgrd.exe:*:Enabled:lmgrd"
"C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe"="C:\Program Files\Kooperativa\KalkZiv\Kalk_ziv.exe:*:Enabled:Kalk_ziv"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Autodesk\backburner\monitor.exe"="C:\Program Files\Autodesk\backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\backburner\manager.exe"="C:\Program Files\Autodesk\backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\backburner\server.exe"="C:\Program Files\Autodesk\backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Teamspeak2_RC2\server_windows.exe"="C:\Program Files\Teamspeak2_RC2\server_windows.exe:*:Enabled:Server"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"E:\Hry\Silverfall\Silverfall.exe"="E:\Hry\Silverfall\Silverfall.exe:*:Enabled:Silverfall"
"C:\Program Files\CrosuS\CrosuSApp.exe"="C:\Program Files\CrosuS\CrosuSApp.exe:*:Enabled:Crosus"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\iTunes\iTunes.exe"="D:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.js - edit -
.js - open -
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-11-29 21:28:16 ----D---- C:\Program Files\trend micro
2010-11-29 21:28:14 ----D---- C:\rsit
2010-11-29 19:27:21 ----A---- C:\WINDOWS\system32\drivers\AmdLLD.sys
2010-11-29 19:27:19 ----D---- C:\Program Files\AMD
2010-11-29 18:42:50 ----A---- C:\WINDOWS\system32\drivers\DrvAgent32.sys
2010-11-23 15:29:25 ----D---- C:\Program Files\Microsoft Silverlight
2010-11-05 15:43:18 ----D---- C:\Program Files\CamStudio
2010-10-31 14:48:19 ----A---- C:\WINDOWS\oodcnt.INI
2010-10-31 11:56:42 ----D---- C:\WINDOWS\system32\oodag
2010-10-31 10:00:37 ----D---- C:\Program Files\OO Software

======List of files/folders modified in the last 1 months======

2010-11-30 09:00:37 ----SD---- C:\WINDOWS\Tasks
2010-11-30 08:55:52 ----D---- C:\WINDOWS\Temp
2010-11-30 08:54:15 ----D---- C:\WINDOWS
2010-11-30 08:53:58 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-29 21:28:16 ----D---- C:\Program Files
2010-11-29 20:54:53 ----A---- C:\WINDOWS\wincmd.ini
2010-11-29 19:27:28 ----SHD---- C:\WINDOWS\Installer
2010-11-29 19:27:27 ----RSH---- C:\boot.ini
2010-11-29 19:27:25 ----HD---- C:\WINDOWS\inf
2010-11-29 19:27:25 ----D---- C:\WINDOWS\system32\drivers
2010-11-29 17:08:46 ----D---- C:\WINDOWS\system32
2010-11-26 13:45:45 ----D---- C:\Program Files\Simulace_2009
2010-11-25 18:48:33 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-11-23 15:29:34 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-11-22 15:36:13 ----D---- C:\Program Files\Mozilla Firefox
2010-11-22 15:36:02 ----A---- C:\WINDOWS\BRWMARK.INI
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Adobe
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Adobe
2010-11-19 15:15:07 ----D---- C:\Program Files\bwin
2010-11-18 17:17:27 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real
2010-11-18 17:17:20 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Real
2010-11-14 21:13:48 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Simulace_2009
2010-11-05 15:51:23 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-03 19:06:16 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-03 17:06:54 ----RSD---- C:\WINDOWS\assembly
2010-11-03 17:05:04 ----D---- C:\Program Files\AEGON Expert 2.0
2010-11-01 11:53:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CPC
2010-11-01 11:49:37 ----D---- C:\DATA_CPC
2010-10-31 23:48:20 ----D---- C:\Program Files\CPC
2010-10-31 10:02:17 ----D---- C:\WINDOWS\Help
2010-10-31 09:43:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-07-20 41728]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-11-20 43872]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-02-01 717296]
R1 avfwot;avfwot; C:\WINDOWS\system32\DRIVERS\avfwot.sys [2010-04-28 102856]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-04-28 124784]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-04-28 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-04-28 60936]
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 cpuz134;cpuz134; \??\C:\WINDOWS\system32\drivers\cpuz134_x32.sys []
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-18 88448]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-18 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-18 55936]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\WINDOWS\system32\DRIVERS\AVerBDA3x.sys [2006-12-14 1171456]
R3 avfwim;AvFw Packet Filter Miniport; C:\WINDOWS\system32\DRIVERS\avfwim.sys [2010-04-28 79432]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-22 17480]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-18 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-12 248192]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S1 seneka;seneka; C:\WINDOWS\system32\drivers\senekangvdknxf.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2010-03-12 30576]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023k.sys [2002-08-12 11136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirFirewallService;Avira FireWall; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [2010-04-28 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2010-04-28 337064]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-28 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-04-28 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-04-28 405672]
R2 Apache2.2;Apache2.2; D:\nydecky.cz\xampp\apache\bin\httpd.exe [2009-12-20 29416]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-23 77944]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-01-15 32256]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R2 KoopPdfService;KoopPdfService; C:\Program Files\Kooperativa\Services\KoopPDFServer.exe [2010-07-04 447488]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-03-12 139632]
R2 MySQL;MySQL; D:\nydecky.cz\xampp\mysql\bin\mysqld.exe [2009-12-20 6095504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2004-05-17 184320]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
S2 MyWebSearchService;My Web Search Service; C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe [2009-08-09 28762]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-11 68096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-22 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#2 Příspěvek od cernohous13 »

Vítám tě u nás Obrázek

Budeme čistit na etapy :wink:
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#3 Příspěvek od Guardian23 »

Děkuji za odpověď a přivítání.

Dle návodu spustím rychlý test, ale bohužel mi program vždy zamrzne po čase cca 1:30, 46.000 zkontrolovaných objektech (z toho 151 infikovaných) a na stejném souboru desktop.ini

Nějaký nápad, prosím? :turned:

------------EDIT------------
A ne, p.o.m.a.l.i.n.k.u. to jede. Tak snad se test zdárně dokončí.


------------Část 1------------
Malwarebytes' Anti-Malware 1.50
http://www.malwarebytes.org

Verze databáze: 5214

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

30.11.2010 12:44:31
logg.txt

Typ kontroly: Rychlý test
Testované objekty: 252986
Uplynulý čas: 2 hodin, 16 minut, 20 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 3
Infikované klíče v registru: 128
Infikované hodnoty v registru: 14
Infikované datové položky v registru: 2
Infikované složky: 48
Infikované soubory: 464

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> No action taken.

Infikované klíče v registru:
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.FunWebProducts) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.FunWebProducts) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seneka (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{67FA02C4-AB30-4e77-A640-78EE8EC8673B} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E3EF3BD5-02F3-4F99-9DAC-A20637DF084D}_is1 (Rogue.RegTool) -> No action taken.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Plugin -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> No action taken.

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#4 Příspěvek od Guardian23 »

------------Část 2------------
Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> No action taken.

Infikované složky:
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\setups (Adware.MyWebSearch) -> No action taken.
c:\program files\regTool (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Email (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg\38 (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\pref (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plugins (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html (Rogue.RegTool) -> No action taken.
c:\program files\ThunMail (Trojan.Agent) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge (Spyware.MarketScore) -> No action taken.

Infikované soubory:
c:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> No action taken.
c:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\dealio toolbar\IE\4.0.2\dealiotoolbarie.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> No action taken.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\all users.windows\Plocha\regTool.lnk (Rogue.RegTool) -> No action taken.
c:\tj.vbs (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekajwfoexno.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekangvdknxf.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\drivers\senekarmdcxeyp.sys (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\ftp_non_crp.exe (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\service-466.exe (Trojan.Downloader) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator\avatar.dat (Adware.MyWebSearch) -> No action taken.
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts\Data\administrator\zbucks.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\m3ntstbr.manifest (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3PATCH.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\avatar.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfadel.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfader.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\common-x.css (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\common.css (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbl.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbr.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\include.js (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\index.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\loader.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\loading.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\logo.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\noflash.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_def.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_roll.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.swf (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\topgrad.gif (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Avatar\COMMON\window.ico (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00024339.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00026D27 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0002DE50 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00030B8A (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0003F926 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\000434B8 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00058F57 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00071143 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\000B050B (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0020256E.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00B5A037 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\00DF1E58 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0167ECEE (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B726BA.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B7290C.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72A73.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72C0A.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\01B72D52 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\02BFB6B2 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0324651C.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\0324672F.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246887.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246A8A.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\03246BF2.bin (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\034B6230 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\setting2.htm.bak (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\settings.dat.bak (Adware.MyWebSearch) -> No action taken.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> No action taken.
c:\program files\regTool\account.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\folderzipper.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\icsharpcode.sharpziplib.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.common.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.processingobjectmodel.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\microsoft.reportviewer.winforms.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\regTool.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\regtool.exe.config (Rogue.RegTool) -> No action taken.
c:\program files\regTool\skybound.gecko.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\system.data.sqlite.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\unins000.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\unins000.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\elNames.xml (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\regdb.s3db (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\regdbnew.s3db (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Data\system.data.sqlite.xml (Rogue.RegTool) -> No action taken.
c:\program files\regTool\Email\vzorovyemail.txt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\imgReg\38\katalog-stranek.sukvos.com.jpg (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\accessiblemarshal.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\crashreporter.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\crashreporter.ini (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dependentlibs.list (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\freebl3.chk (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\freebl3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\ia2marshal.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\javaxpcom.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\javaxpcomglue.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\js.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\js3250.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\LICENSE (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozcrt19.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozctl.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\mozctlx.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nspr-config (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nspr4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nss3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssckbi.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssdbm3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\nssutil3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\platform.ini (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plc4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plds4.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\README.txt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\redit.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\smime3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\softokn3.chk (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\softokn3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\sqlite3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\ssl3.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\update.locale (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\updater.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpcom.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpcshell.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpidl.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpt_dump.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xpt_link.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xul.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xulrunner-stub.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\xulrunner.exe (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\classic.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\classic.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\comm.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\comm.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\en-US.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\en-us.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\pippki.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\pippki.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\toolkit.jar (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\chrome\toolkit.manifest (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\accessibility-msaa.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\accessibility.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\alerts.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\appshell.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\appstartup.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\autocomplete.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\autoconfig.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\caps.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\chardet.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\chrome.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\commandhandler.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\commandlines.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\composer.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\compreg.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\contentprefs.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_html.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_htmldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xmldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xslt.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\content_xtf.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\cookie.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\directory.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\docshell_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_canvas.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_core.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_css.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_events.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_geolocation.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_html.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_json.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_loadsave.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_offline.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_range.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_sidebar.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_storage.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_stylesheets.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_svg.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_threads.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_traversal.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_views.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xbl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xpath.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\dom_xul.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\downloads.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\editor.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\embed_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\extensions.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\exthandler.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\exthelper.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\fastfind.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\feedprocessor.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\feeds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\find.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\gfx.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\htmlparser.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\imgicon.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\imglib2.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\inspector.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\intl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jar.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jsconsole-clhandler.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\jsdservice.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_printing.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_xul.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\layout_xul_tree.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\locale.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\loginmgr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\lwbrk.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mimetype.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mozbrwsr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\mozfind.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_about.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_cache.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_cookie.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_dns.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_file.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_ftp.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_http.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_res.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_socket.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_strconv.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_viewsource.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\necko_wifi.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\networkgeolocationprovider.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsaddonrepository.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsbadcerthandler.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsblocklistservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nscontentdispatchchooser.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nscontentprefservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsdefaultclh.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsdownloadmanagerui.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsextensionmanager.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nshandlerservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nshelperappdlg.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nslivemarkservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nslogininfo.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsloginmanager.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsloginmanagerprompter.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsplacesdbflush.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nspostupdatewin.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsprogressdialog.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsproxyautoconfig.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nssearchservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nssearchsuggestions.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nstaggingservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nstrytoclose.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsupdateservice.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsurlformatter.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nswebhandlerapp.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\nsxulappinstall.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\oji.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\parentalcontrols.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pipboot.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pipnss.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pippki.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\places.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\plugin.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pluginglue.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\pref.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\prefetch.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\profile.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\proxyobject.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\rdf.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\satchel.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\saxparser.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\shistory.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\spellchecker.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage-legacy.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage-mozstorage.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\storage.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\toolkitprofile.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\toolkitsearch.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txexsltregexfunctions.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txmgr.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\txtsvc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\uconv.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\unicharutil.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\update.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\uriloader.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\urlformatter.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webbrowserpersist.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webbrowser_core.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\webshell_idls.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\widget.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\windowds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\windowwatcher.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_base.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_components.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_ds.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_io.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_system.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_thread.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpcom_xpti.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpconnect.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpinstall.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xpti.dat (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xulapp.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xulapp_setup.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xuldoc.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\xultmpl.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\components\zipwriter.xpt (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig\platform.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\autoconfig\prefcalls.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\pref\xulrunner.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\localstore.rdf (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome\userchrome-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\chrome\usercontent-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\localstore.rdf (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome\userchrome-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome\usercontent-example.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries\en-US.aff (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\dictionaries\en-US.dic (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\all.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\security-prefs.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\greprefs\xpinstall.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\debug.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\downloadlastdir.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\downloadutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\iso8601dateutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\microformats.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\placesdbutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\pluralform.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\spatialnavigation.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\utils.js (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\windowdraggingutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\modules\xpcomutils.jsm (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\plugins\npnul32.dll (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\arrow.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\arrowd.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\broken-image.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\charsetalias.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\charsetdata.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\contenteditable.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\designmode.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\editoroverride.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\forms.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\grabber.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\hiddenwindow.html (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\langgroups.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\language.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\loading-image.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\mathml.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\quirk.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\svg.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-after.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-column-before.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-after.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-add-row-before.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-column.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row-active.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row-hover.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\table-remove-row.gif (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\ua.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\viewsource.css (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\wincharset.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd\mathml.dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\dtd\xhtml11.dtd (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40latin1.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40special.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\html40symbols.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\htmlentityversions.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\mathml20.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\entitytables\transliterate.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfont.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstandardsymbolsl.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixnonunicode.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixsize1.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontsymbol.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\fonts\mathfontunicode.properties (Rogue.RegTool) -> No action taken.
c:\program files\regTool\xulrunner\res\html\folder.png (Rogue.RegTool) -> No action taken.
c:\program files\ThunMail\testabd.dll.vir (Trojan.Agent) -> No action taken.
c:\program files\ThunMail\testabd.exe.vir (Trojan.Agent) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\aplikace regtool na internetu.url (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\odinstalovat aplikaci regtool.lnk (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool\regTool.lnk (Rogue.RegTool) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\about relevantknowledge.lnk (Spyware.MarketScore) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\privacy policy and user license agreement.lnk (Spyware.MarketScore) -> No action taken.
c:\documents and settings\all users.windows\nabídka start\Programy\relevantknowledge\Support.lnk (Spyware.MarketScore) -> No action taken.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#5 Příspěvek od cernohous13 »

:o pěkná sbírka - s tím ti musel někdo pomáhat :D
pokud jsi program ještě nezavřel, tak:
Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené

vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych taky rád viděl :)
(jestli už je zavřený, tak MBAM spustit znovu - dát Kompletní kontrola...)
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#6 Příspěvek od Guardian23 »

3 roky jsem na to prakticky nesáhl (léčba apod.). Spoléhal jsem na antivir :) A zatím mi nikdo neukradl peníze z internetového bankovnictví, tak jsem si říkal, že je asi všechno O.K. :D

Tady je log. Jinak to hlásilo, že některé ponožky nemohly být odstraněny :) A pak mám ještě restartovat...zatím s restartem počkám :)

***1/2***
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Verze databáze: 5214

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.13

30.11.2010 13:43:56
mbam-log-2010-11-30 (13-43-56).txt

Typ kontroly: Rychlý test
Testované objekty: 252986
Uplynulý čas: 2 hodin, 16 minut, 20 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 3
Infikované klíče v registru: 128
Infikované hodnoty v registru: 14
Infikované datové položky v registru: 2
Infikované složky: 48
Infikované soubory: 464

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch)

-> Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) ->

Not selected for removal.

Infikované klíče v registru:
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWe

bSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted

successfully.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC2

01FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for

removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not

selected for removal.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}

(PUP.FunWebProducts) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6

FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows

er Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0139

8B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (Adware.WidgiToolbar) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B1

8EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2556

0540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF0

5104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApprove

d\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo)

-> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seneka (Trojan.Agent)

-> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\seneka (Malware.Trace) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low

Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.Out

lookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.Outloo

kAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08

d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) ->

Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{67FA02C4-AB30-4e77-A640-78EE8EC8673B}

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E3E

F3BD5-02F3-4F99-9DAC-A20637DF084D}_is1 (Rogue.RegTool) -> Quarantined and

deleted successfully.

Infikované hodnoty v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web

Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web

Search Bar Search Scope Monitor -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearc

h Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch

Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearc

h Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Plugin -> Quarantined

and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

(Adware.WidgiToolbar) -> Value: {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D}

(Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D}

(Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet

Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA}

(Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} ->

Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet

Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) ->

Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value:

f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet

Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) ->

Value: FunWebProducts -> Quarantined and deleted successfully.

Infikované datové položky v registru:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath

(Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k

netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on

reboot.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath

(Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k

netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on

reboot.

Infikované složky:
c:\documents and settings\administrator.lenka\data aplikací\funwebproducts

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\funwebproducts\Shared\Cache (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Delete on

reboot.
c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\setups (Adware.MyWebSearch) -> Quarantined

and deleted successfully.
c:\program files\regTool (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\Data (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\Email (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\imgReg (Rogue.RegTool) -> Quarantined and deleted

successfully.
c:\program files\regTool\imgReg\38 (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner\chrome (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\components (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\pref (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\chrome (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US\chrome

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\modules (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\plugins (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\xulrunner\res\dtd (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\res\html (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\ThunMail (Trojan.Agent) -> Quarantined and deleted

successfully.
c:\documents and settings\all users.windows\nabídka start\Programy\regTool

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge (Spyware.MarketScore) -> Quarantined and

deleted successfully.

Infikované soubory:
c:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) ->

Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mozilla firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch)

-> Delete on reboot.
c:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\mywebsearch\bar\1.bin\F3HTMLMU.DLL (PUP.FunWebProducts) ->

Not selected for removal.
c:\program files\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL (Adware.MyWebSearch) ->

Delete on reboot.
c:\program files\dealio toolbar\IE\4.0.2\dealiotoolbarie.dll

(Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\Plocha\regTool.lnk

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\tj.vbs (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\seneka.sys (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\WINDOWS\system32\drivers\senekajwfoexno.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\senekangvdknxf.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\drivers\senekarmdcxeyp.sys (Trojan.Agent) ->

Quarantined and deleted successfully.
c:\WINDOWS\system32\ftp_non_crp.exe (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\WINDOWS\system32\service-466.exe (Trojan.Downloader) -> Quarantined and

deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator\avatar.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\documents and settings\administrator.lenka\data

aplikací\funwebproducts\Data\administrator\zbucks.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\cursormaniabtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\myfuncardsimbtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\smileycentralbtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared\Cache\webfettibtn.html

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3AUXSTB.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3DLGHK.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\m3ffxtbr.manifest

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\m3ntstbr.manifest

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3PATCH.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\avatar.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfadel.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\bgfader.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\common-x.css

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\common.css

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbl.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\cornerbr.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\ext_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\include.js

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\index.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\loader.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\loading.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\logo.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\max_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\min_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\noflash.htm

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_def.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\res_roll.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\spacer.swf

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\topgrad.gif

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Avatar\COMMON\window.ico

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00024339.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00026D27 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0002DE50 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00030B8A (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0003F926 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\000434B8 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00058F57 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00071143 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\000B050B (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0020256E.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00B5A037 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\00DF1E58 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0167ECEE (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B726BA.bin (Adware.MyWebSearch) ->


Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#7 Příspěvek od Guardian23 »

***2/2***
Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B7290C.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72A73.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72C0A.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\01B72D52 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\02BFB6B2 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0324651C.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\0324672F.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246887.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246A8A.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\03246BF2.bin (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\034B6230 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\setting2.htm.bak

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch)

-> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\settings.dat.bak

(Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) ->

Quarantined and deleted successfully.
c:\program files\regTool\account.dll (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\folderzipper.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\icsharpcode.sharpziplib.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.common.dll (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.processingobjectmodel.dll

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\microsoft.reportviewer.winforms.dll

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\regTool.exe (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\regtool.exe.config (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\skybound.gecko.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\system.data.sqlite.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\unins000.dat (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\unins000.exe (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\Data\elNames.xml (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\Data\regdb.s3db (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\program files\regTool\Data\regdbnew.s3db (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\Data\system.data.sqlite.xml (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\Email\vzorovyemail.txt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\imgReg\38\katalog-stranek.sukvos.com.jpg

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\accessiblemarshal.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\crashreporter.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\crashreporter.ini (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dependentlibs.list (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\freebl3.chk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\freebl3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\ia2marshal.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\javaxpcom.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\javaxpcomglue.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\js.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\js3250.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\LICENSE (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\mozcrt19.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\mozctl.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\mozctlx.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nspr-config (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nspr4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\nss3.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\nssckbi.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nssdbm3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\nssutil3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\platform.ini (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\plc4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\plds4.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\README.txt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\redit.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\smime3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\softokn3.chk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\softokn3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\sqlite3.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\ssl3.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\update.locale (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\updater.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpcom.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xpcshell.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpidl.exe (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xpt_dump.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xpt_link.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xul.dll (Rogue.RegTool) -> Quarantined

and deleted successfully.
c:\program files\regTool\xulrunner\xulrunner-stub.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\xulrunner.exe (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\classic.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\classic.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\comm.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\comm.manifest (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\en-US.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\en-us.manifest (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\pippki.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\pippki.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\toolkit.jar (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\chrome\toolkit.manifest (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\accessibility-msaa.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\accessibility.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\alerts.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\appshell.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\appstartup.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\autocomplete.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\autoconfig.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\caps.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\chardet.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\chrome.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\commandhandler.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\commandlines.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\composer.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\compreg.dat (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\contentprefs.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_html.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_htmldoc.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xmldoc.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xslt.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\content_xtf.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\cookie.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\directory.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\docshell_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_base.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_canvas.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_core.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_css.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_events.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_geolocation.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_html.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_json.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_loadsave.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_offline.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_range.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_sidebar.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_storage.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_stylesheets.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_svg.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_threads.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_traversal.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_views.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xbl.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xpath.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\dom_xul.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\downloads.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\editor.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\embed_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\extensions.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\exthandler.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\exthelper.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\fastfind.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\feedprocessor.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\feeds.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\find.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\gfx.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\htmlparser.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\imgicon.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\imglib2.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\inspector.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\intl.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jar.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jsconsole-clhandler.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\jsdservice.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_printing.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_xul.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\layout_xul_tree.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\locale.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\loginmgr.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\lwbrk.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mimetype.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mozbrwsr.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\mozfind.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_about.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_cache.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_cookie.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_dns.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_file.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_ftp.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_http.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_res.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_socket.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_strconv.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_viewsource.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\necko_wifi.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\networkgeolocationprovider.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsaddonrepository.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsbadcerthandler.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsblocklistservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nscontentdispatchchooser.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nscontentprefservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsdefaultclh.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsdownloadmanagerui.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsextensionmanager.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nshandlerservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nshelperappdlg.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nslivemarkservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nslogininfo.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsloginmanager.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsloginmanagerprompter.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsplacesdbflush.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nspostupdatewin.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsprogressdialog.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsproxyautoconfig.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nssearchservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nssearchsuggestions.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nstaggingservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nstrytoclose.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsupdateservice.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsurlformatter.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nswebhandlerapp.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\nsxulappinstall.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\oji.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\parentalcontrols.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pipboot.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pipnss.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pippki.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\places.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\plugin.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pluginglue.js (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\pref.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\prefetch.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\profile.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\proxyobject.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\rdf.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\satchel.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\saxparser.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\shistory.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\spellchecker.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage-legacy.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage-mozstorage.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\storage.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\toolkitprofile.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\toolkitsearch.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txexsltregexfunctions.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txmgr.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\txtsvc.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\uconv.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\unicharutil.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\update.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\uriloader.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\urlformatter.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webbrowserpersist.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webbrowser_core.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\webshell_idls.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\widget.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\windowds.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\windowwatcher.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_base.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_components.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_ds.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_io.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_system.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_thread.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpcom_xpti.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpconnect.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpinstall.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xpti.dat (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xulapp.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xulapp_setup.xpt

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xuldoc.xpt (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\xultmpl.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\components\zipwriter.xpt (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig\platform.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\autoconfig\prefcalls.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\pref\xulrunner.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\localstore.rdf

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\chrome\userchrome-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\chrome\usercontent-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\defaults\profile\US\localstore.rdf

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\US\chrome\userchrome-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\defaults\profile\US\chrome\usercontent-example.css

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries\en-US.aff (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\dictionaries\en-US.dic (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\all.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\security-prefs.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\greprefs\xpinstall.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\debug.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\downloadlastdir.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\downloadutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\iso8601dateutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\microformats.js (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\placesdbutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\pluralform.jsm (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\spatialnavigation.js

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\utils.js (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\windowdraggingutils.jsm

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\modules\xpcomutils.jsm (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\plugins\npnul32.dll (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\arrow.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\arrowd.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\broken-image.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\charsetalias.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\charsetdata.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\contenteditable.css (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\designmode.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\editoroverride.css (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\forms.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\grabber.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\hiddenwindow.html (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\html.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\langgroups.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\language.properties (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\loading-image.gif (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\mathml.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\quirk.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\svg.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-after.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-column-before.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-after.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-add-row-before.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-column.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row-active.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row-hover.gif

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\table-remove-row.gif (Rogue.RegTool)

-> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\ua.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\viewsource.css (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\wincharset.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\dtd\mathml.dtd (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\dtd\xhtml11.dtd (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables\html40latin1.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\html40special.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\html40symbols.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\htmlentityversions.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\entitytables\mathml20.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\entitytables\transliterate.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfont.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\fonts\mathfontstandardsymbolsl.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program

files\regTool\xulrunner\res\fonts\mathfontstixnonunicode.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontstixsize1.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontsymbol.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\fonts\mathfontunicode.properties

(Rogue.RegTool) -> Quarantined and deleted successfully.
c:\program files\regTool\xulrunner\res\html\folder.png (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\program files\ThunMail\testabd.dll.vir (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\program files\ThunMail\testabd.exe.vir (Trojan.Agent) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\aplikace regtool na internetu.url (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\odinstalovat aplikaci regtool.lnk (Rogue.RegTool) ->

Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\regTool\regTool.lnk (Rogue.RegTool) -> Quarantined and

deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\about relevantknowledge.lnk

(Spyware.MarketScore) -> Quarantined and deleted successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\privacy policy and user license

agreement.lnk (Spyware.MarketScore) -> Quarantined and deleted

successfully.
c:\documents and settings\all users.windows\nabídka

start\Programy\relevantknowledge\Support.lnk (Spyware.MarketScore) ->

Quarantined and deleted successfully.

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#8 Příspěvek od cernohous13 »

:arrow: Restart potřebuje na vyčištění paměti.

:arrow: pokračujeme
Stáhni si Obrázek ComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#9 Příspěvek od Guardian23 »

Po skončění úlohy se objevila modrá obrazovka smrti, tak jsem se lekl. Ale po resetu systém naběhl. Snad to při dalším restartu/vypnutí taky dobře naběhne.

LOG
ComboFix 10-11-29.05 - Administrator 30.11.2010 16:02:07.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1263 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator.LENKA\Plocha\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira FireWall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio
c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio\res\widgets.xml
c:\documents and settings\Administrator.LENKA\Data aplikací\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
c:\documents and settings\Administrator.LENKA\Plocha\Jsou rozdíly v nakupování ve městě a na vesnici.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vrátit starou zářivku je umění.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vytápění dřevem prudce zdražuje.doc
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\components\config.ini
c:\program files\Dealio Toolbar\FF\components\dealioToolbarFF.dll
c:\program files\Dealio Toolbar\FF\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\components\IFBHOWidgiToolbar.xpt
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\login.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\parser.js
c:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\separator.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\4.0.2\config.ini
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{00F22D4A-DF18-4668-A0DA-B5F7B75CAF72}\install.rdf
c:\program files\Search Settings
c:\program files\Search Settings\FF\components\IFBHOSearch.xpt
c:\program files\Search Settings\FF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Search Settings\FF\components\IFHelperPreferences.xpt
c:\program files\Search Settings\FF\components\SearchSettingsFF.dll
c:\program files\Search Settings\FF\chrome.manifest
c:\program files\Search Settings\FF\chrome\content\plugin.js
c:\program files\Search Settings\FF\chrome\content\plugin.xul
c:\program files\Search Settings\FF\chrome\content\protection.js
c:\program files\Search Settings\FF\chrome\content\utils.js
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Search Settings\FF\install.rdf
c:\program files\Search Settings\SearchSettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\program files\Search Settings\SearchSettingsRes409.VIR
c:\windows\system32\senekaiwqvvrcv.dat
c:\windows\system32\senekamdwxtiqj.dat
c:\windows\system32\senekatqxlxyef.dat
c:\windows\system32\senekauplvbuwm.dat
c:\windows\system32\senekawhkypbiv.dat

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-28 do 2010-11-30 )))))))))))))))))))))))))))))))
.

2010-11-30 15:01 . 2010-11-30 15:01 -------- d-----w- C:\32788R22FWJFW
2010-11-30 13:22 . 2010-11-30 13:44 -------- d-----w- c:\program files\HDD Regenerator
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 09:14 . 2010-11-30 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-29 20:28 . 2010-11-30 08:00 -------- d-----w- c:\program files\trend micro
2010-11-29 20:28 . 2010-11-29 20:28 -------- d-----w- C:\rsit
2010-11-29 18:27 . 2007-06-29 13:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2010-11-29 18:27 . 2010-11-29 18:27 -------- d-----w- c:\program files\AMD
2010-11-29 17:42 . 2010-11-29 17:42 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-11-29 17:42 . 2010-11-29 17:42 -------- d-----w- c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\eSupport.com
2010-11-23 14:29 . 2010-11-23 14:29 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-05 14:43 . 2010-11-05 23:17 -------- d-----w- c:\program files\CamStudio

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-24 08:09 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-24 08:09 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-08-04 11:31 . 2009-02-05 17:39 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-02-08 133104]
"QIP2005"="c:\program files\QIP\qip.exe" [2008-12-09 3259392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-04 30192]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-17 148888]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-03-12 119152]
"LiveZilla"="c:\program files\LiveZilla\LiveZilla.exe" [2010-05-17 2651576]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-10-24 202256]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files (x86)\OpenOffice.org 2.4\program\quickstart.exe [2008-5-30 393216]

c:\documents and settings\Administrator.LENKA\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]

c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-11 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-5-28 606208]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-12 813584]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\bwin\\StartbwinPoker.exe"=
"d:\\hl22\\HALF LIFE 2\\hl2.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\CrosuS\\CrosuSApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [26.9.2009 14:27 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [26.9.2009 14:27 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.2.2009 0:38 717296]
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [28.4.2010 20:05 102856]
R2 AntiVirFirewallService;Avira FireWall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [28.4.2010 20:05 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [28.4.2010 20:05 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [26.8.2009 21:51 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [28.4.2010 20:05 405672]
R2 Apache2.2;Apache2.2;d:\nydecky.cz\xampp\apache\bin\httpd.exe [17.2.2010 15:44 29416]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16.12.2009 17:38 375296]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [26.9.2010 13:32 20328]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 10:16 1107336]
R2 KoopPdfService;KoopPdfService;c:\program files\Kooperativa\Services\KoopPDFServer.exe [4.7.2010 10:38 447488]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [6.11.2008 19:00 1171456]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [28.4.2010 20:05 79432]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [29.11.2010 18:42 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5.2.2009 18:39 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [13.4.2010 14:20 30576]
S4 Swentuip;Swentuip; [x]
.
Obsah adresáře 'Naplánované úlohy'

2009-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-05-02 c:\windows\Tasks\Install.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2010-04-28 19:48]

2010-07-03 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-03-12 16:41]

2010-04-13 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2010-03-12 16:41]

2010-11-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-11-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-01-20 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 16:29]
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.cz
FF - component: c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\documents and settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Ranky: ranky@ranky.cz - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\ranky@ranky.cz
FF - Extension: PimpZilla: {a02c0c70-605c-11da-8cd6-0800200c9a66} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Counterpixel: counterpixel@jabubo.de - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\counterpixel@jabubo.de
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: Cooliris: piclens@cooliris.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com
FF - Extension: SEOProfesional: seo@profesional - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\seo@profesional
FF - Extension: 20-20 3D Viewer: 2020Player@2020Technologies.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\2020Player@2020Technologies.com
FF - Extension: Collabim: {db0832f2-613f-4afb-8b6a-155fe76eb32e} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{db0832f2-613f-4afb-8b6a-155fe76eb32e}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-netmon.exe - c:\program files\netmon\netmon.exe
HKLM-Run-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
AddRemove-Escape Whisper Valley - e:\hry\popgames\Escape Whisper Valley\PopUninstall.exe
AddRemove-Hledik - Poradce - makléř FAC - c:\gen_makler\\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-30 16:14
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-484763869-1482476501-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CAF28C9-EB0A-7D46-95A8-6DBEC787F657}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG06.00.00.01WORKSTATION"="3523683F98B7D088E5D186AA3446897566BA45D8E7FA61F05616BE33CFF972057601695E63AA1FBE0FE17D8FF920D84996CD24ECA790BE9C3C908301E2D406AFB4B30CBEF9883E4B5723A41163A8585E93D416FD50CE03EA2F0DD7DB16755703552BA012E8CE5950FA0748E7602C40AC8DE184EF55F49250FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555A2D97226D213B555A9C6AECB7A5D1407F9EF2B1EA2605560695DE24B9A023BAD660FDA1F3393A48652442AE2F83DB5ACDF9C50E8E6AB9037BD08EFF3BD097145204552A52D8398B789EFB5844BE30974EE1E7C0B5F3113C9268F95C978EB33D42AEC4C20D5D13D7A261654F5A0325875DA7D34957459CA6DCB1EF40A36831DA541EFA8923E65F9B39A8041A45041F7CA69093180E28C1C97E722E1D2B9293DA936FE79E44E2BAC6D6BC1EAE085ACB239F450DE26BAB7DCE34B4CE728193B1AF26C8C8463BF11A6D3B0AB74DF401647246BA9DDC2E1CE5811589443F0BC9D2A3BDBCFC43FA28C2B381AD8363D5522E69750AC837B11444E8185B4E678E4355A5D12C2690DD815F58E68A33C736BF837C03838D754D4146FBCE02A76EEA0ED8A592F2654C59925B1F06F2C44667EC652F04E6C17B90D3CE66D0738CDE657B68D52E6FC9CC36F3C019B99D7445A5F3EC71DD02FB279703D4B62AC6377D7C281AD91800E0B4839DEF76FE34E6178B09118E192A94E45851CAE8E9877389E6FC324035A64A1F72A951F72607B79CDE97BBA7BF7484233AA64928825820378417A24B5E2CF0F5CC76A75CB32101A4D5837984CFCBB1BBE90226E0DC355020AEBA3CE5D20E2BCDFEDED6A4995FE084B1B850FDAAF7B9AC6BA682E78F586145BF9C03ED329F343544BB2645CD5813A81A4ABF0CE323D340C044BAF4FD3F1C9D5C95AFC92AA1FF16CE2D13A1854145C0DBE7205F73B0211361764C5B788B2E7CA0DF80C3A6544CBC20BE6BAB707F54D6F04A5844794888D4FF5D3B8FCD32E69ECC7AC5F102C0585D1ED10A616F6AA220F64961D549BD539467539C28D0807FAD2D6885E79694A0DFB0CF23236C07BA0B32399F15644B3D9EB3EB992FC8C2BFD7965A16504173DFC043635873B1675460BD987182E933067F7CB804C02DCC6083FF5134560464EAA13948342EE3DE64028F1BC99DA251B8E85713B0677084B63E7DEFCC0611CAF9B35A08D75BC8EE4F37E2D9A7505258AAF90511ACA5CB2F00D9AC87F907D51D90B5B2B07A43877C778679E859CF45856DFFDE55399D291AF3762B344E0D3AF0866D8D427C814782A98A2AD657518931DE612FA2266A2F2C6C6AF6E72D12299B75067962A4F2AA8EE54CF1727DA81C0BE4179B24197B6B3B854D4213CF5CC822D1F2239CF9978"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1408)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1472)
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(4872)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msi.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft ActiveSync\Wcescomm.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
d:\nydecky.cz\xampp\mysql\bin\mysqld.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\windows\system32\wscntfy.exe
c:\program files\Firebird\bin\fbserver.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Avira\AntiVir Desktop\usrreq.exe
c:\program files\Avira\AntiVir Desktop\checkt.exe
.
**************************************************************************
.
Celkový čas: 2010-11-30 16:18:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-30 15:18

Před spuštěním: 3 047 518 208
Po spuštění: Volných bajtů: 10 603 380 736

- - End Of File - - 7D72ED2BB228563A27BCF05ED96B05E1

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#10 Příspěvek od cernohous13 »

Jak velký problém jsou vymazané *.doc?
c:\documents and settings\Administrator.LENKA\Plocha\Jsou rozdíly v nakupování ve městě a na vesnici.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vrátit starou zářivku je umění.doc
c:\documents and settings\Administrator.LENKA\Plocha\Vytápění dřevem prudce zdražuje.doc

je nutné je vrátit? na ostatní připravím script
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#11 Příspěvek od Guardian23 »

Těchto souborů jsem se chtěl dávno zbavit, ale nešly mi smazat. Takže díky za odstranění :)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#12 Příspěvek od cernohous13 »

:arrow: Pokud netrváš na vyhledávači od c:\program files\Ask.com - odinstaluj (nemáme ho rádi)

:arrow: Otevři Poznámkový blok (Notepad) a zkopíruj celý zelený text z "CFscriptu".
Soubor ulož na plochu jako CFscript.txt a jeho ikonu přetáhni myší nad ikonu ComboFixu - tam pusť.
Obrázek
ComboFix se spustí - počkej na log a vlož ho sem.
CFscript

Kód: Vybrat vše

KillAll::

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"NeroFilterCheck"=-
"SunJavaUpdateSched"=-
"ISUSPM Startup"=-
"ISUSScheduler"=-
"QuickTime Task"=-
"TkBellExe"=-

Driver::
Firebird Guardian
Firebird Server
Swentuip

File::
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\Install.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

RegNull::
[HKEY_USERS\S-1-5-21-484763869-1482476501-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7CAF28C9-EB0A-7D46-95A8-6DBEC787F657}*]
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#13 Příspěvek od Guardian23 »

Provedeno.

Je to všechno? :)

Pokud ano, tak moc děkuji.

Kdyžtak ještě zasílám log.
ComboFix 10-11-29.05 - Administrator 30.11.2010 19:20:46.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1235 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator.LENKA\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator.LENKA\Plocha\CFscript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira FireWall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}

FILE ::
"c:\windows\Tasks\AppleSoftwareUpdate.job"
"c:\windows\Tasks\Install.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\Tasks\Install.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-484763869-1482476501-725345543-500.job
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_Swentuip


((((((((((((((((((((((((( Soubory vytvořené od 2010-10-28 do 2010-11-30 )))))))))))))))))))))))))))))))
.

2010-11-30 13:22 . 2010-11-30 13:44 -------- d-----w- c:\program files\HDD Regenerator
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-30 09:14 . 2010-11-30 13:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-30 09:14 . 2010-11-30 09:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 09:14 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-29 20:28 . 2010-11-30 08:00 -------- d-----w- c:\program files\trend micro
2010-11-29 20:28 . 2010-11-29 20:28 -------- d-----w- C:\rsit
2010-11-29 18:27 . 2007-06-29 13:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2010-11-29 18:27 . 2010-11-29 18:27 -------- d-----w- c:\program files\AMD
2010-11-29 17:42 . 2010-11-29 17:42 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-11-29 17:42 . 2010-11-29 17:42 -------- d-----w- c:\documents and settings\Administrator.LENKA\Local Settings\Data aplikací\eSupport.com
2010-11-23 14:29 . 2010-11-23 14:29 -------- d-----w- c:\program files\Microsoft Silverlight
2010-11-05 14:43 . 2010-11-05 23:17 -------- d-----w- c:\program files\CamStudio

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-24 08:09 . 2003-03-18 21:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-24 08:09 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-08-04 11:31 . 2009-02-05 17:39 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QIP2005"="c:\program files\QIP\qip.exe" [2008-12-09 3259392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-04 30192]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-03-12 119152]
"LiveZilla"="c:\program files\LiveZilla\LiveZilla.exe" [2010-05-17 2651576]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files (x86)\OpenOffice.org 2.4\program\quickstart.exe [2008-5-30 393216]

c:\documents and settings\Administrator.LENKA\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-5-14 384512]

c:\documents and settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-11 113664]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2010-5-28 606208]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-12 813584]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ OODBS\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\bwin\\StartbwinPoker.exe"=
"d:\\hl22\\HALF LIFE 2\\hl2.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\backburner\\server.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\CrosuS\\CrosuSApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [26.9.2009 14:27 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [26.9.2009 14:27 5248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.2.2009 0:38 717296]
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [28.4.2010 20:05 102856]
R2 AntiVirFirewallService;Avira FireWall;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [28.4.2010 20:05 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [28.4.2010 20:05 337064]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [26.8.2009 21:51 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [28.4.2010 20:05 405672]
R2 Apache2.2;Apache2.2;d:\nydecky.cz\xampp\apache\bin\httpd.exe [17.2.2010 15:44 29416]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [16.12.2009 17:38 375296]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [26.9.2010 13:32 20328]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 10:16 1107336]
R2 KoopPdfService;KoopPdfService;c:\program files\Kooperativa\Services\KoopPDFServer.exe [4.7.2010 10:38 447488]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [6.11.2008 19:00 1171456]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [28.4.2010 20:05 79432]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [29.11.2010 18:42 23456]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5.2.2009 18:39 30192]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [13.4.2010 14:20 30576]
.
Obsah adresáře 'Naplánované úlohy'

2010-07-03 c:\windows\Tasks\Microsoft_Hardware_Launch_IcePick_exe.job
- c:\program files\Microsoft LifeCam\IcePick.exe [2010-03-12 16:41]

2010-04-13 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2010-03-12 16:41]
.
.
------- Doplňkový sken -------
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.cz
FF - component: c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\documents and settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Ranky: ranky@ranky.cz - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\ranky@ranky.cz
FF - Extension: PimpZilla: {a02c0c70-605c-11da-8cd6-0800200c9a66} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{a02c0c70-605c-11da-8cd6-0800200c9a66}
FF - Extension: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Extension: Counterpixel: counterpixel@jabubo.de - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\counterpixel@jabubo.de
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: Cooliris: piclens@cooliris.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\piclens@cooliris.com
FF - Extension: SEOProfesional: seo@profesional - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\seo@profesional
FF - Extension: 20-20 3D Viewer: 2020Player@2020Technologies.com - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\2020Player@2020Technologies.com
FF - Extension: Collabim: {db0832f2-613f-4afb-8b6a-155fe76eb32e} - c:\documents and settings\Administrator.LENKA\Data aplikací\Mozilla\Firefox\Profiles\2sdhw63p.default\extensions\{db0832f2-613f-4afb-8b6a-155fe76eb32e}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-30 19:29
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG06.00.00.01WORKSTATION"="3523683F98B7D088E5D186AA3446897566BA45D8E7FA61F05616BE33CFF972057601695E63AA1FBE0FE17D8FF920D84996CD24ECA790BE9C3C908301E2D406AFB4B30CBEF9883E4B5723A41163A8585E93D416FD50CE03EA2F0DD7DB16755703552BA012E8CE5950FA0748E7602C40AC8DE184EF55F49250FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B555A2D97226D213B555A9C6AECB7A5D1407F9EF2B1EA2605560695DE24B9A023BAD660FDA1F3393A48652442AE2F83DB5ACDF9C50E8E6AB9037BD08EFF3BD097145204552A52D8398B789EFB5844BE30974EE1E7C0B5F3113C9268F95C978EB33D42AEC4C20D5D13D7A261654F5A0325875DA7D34957459CA6DCB1EF40A36831DA541EFA8923E65F9B39A8041A45041F7CA69093180E28C1C97E722E1D2B9293DA936FE79E44E2BAC6D6BC1EAE085ACB239F450DE26BAB7DCE34B4CE728193B1AF26C8C8463BF11A6D3B0AB74DF401647246BA9DDC2E1CE5811589443F0BC9D2A3BDBCFC43FA28C2B381AD8363D5522E69750AC837B11444E8185B4E678E4355A5D12C2690DD815F58E68A33C736BF837C03838D754D4146FBCE02A76EEA0ED8A592F2654C59925B1F06F2C44667EC652F04E6C17B90D3CE66D0738CDE657B68D52E6FC9CC36F3C019B99D7445A5F3EC71DD02FB279703D4B62AC6377D7C281AD91800E0B4839DEF76FE34E6178B09118E192A94E45851CAE8E9877389E6FC324035A64A1F72A951F72607B79CDE97BBA7BF7484233AA64928825820378417A24B5E2CF0F5CC76A75CB32101A4D5837984CFCBB1BBE90226E0DC355020AEBA3CE5D20E2BCDFEDED6A4995FE084B1B850FDAAF7B9AC6BA682E78F586145BF9C03ED329F343544BB2645CD5813A81A4ABF0CE323D340C044BAF4FD3F1C9D5C95AFC92AA1FF16CE2D13A1854145C0DBE7205F73B0211361764C5B788B2E7CA0DF80C3A6544CBC20BE6BAB707F54D6F04A5844794888D4FF5D3B8FCD32E69ECC7AC5F102C0585D1ED10A616F6AA220F64961D549BD539467539C28D0807FAD2D6885E79694A0DFB0CF23236C07BA0B32399F15644B3D9EB3EB992FC8C2BFD7965A16504173DFC043635873B1675460BD987182E933067F7CB804C02DCC6083FF5134560464EAA13948342EE3DE64028F1BC99DA251B8E85713B0677084B63E7DEFCC0611CAF9B35A08D75BC8EE4F37E2D9A7505258AAF90511ACA5CB2F00D9AC87F907D51D90B5B2B07A43877C778679E859CF45856DFFDE55399D291AF3762B344E0D3AF0866D8D427C814782A98A2AD657518931DE612FA2266A2F2C6C6AF6E72D12299B75067962A4F2AA8EE54CF1727DA81C0BE4179B24197B6B3B854D4213CF5CC822D1F2239CF9978"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1404)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(1460)
c:\program files\Avira\AntiVir Desktop\avsda.dll

- - - - - - - > 'explorer.exe'(4568)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\DRIVERS\CDANTSRV.EXE
c:\program files\Firebird\bin\fbguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft LifeCam\MSCamS32.exe
d:\nydecky.cz\xampp\mysql\bin\mysqld.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\windows\RTHDCPL.EXE
c:\program files\Firebird\bin\fbserver.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft ActiveSync\Wcescomm.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Avira\AntiVir Desktop\checkt.exe
.
**************************************************************************
.
Celkový čas: 2010-11-30 19:35:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-11-30 18:35
ComboFix2.txt 2010-11-30 15:18

Před spuštěním: Volných bajtů: 10 554 580 992
Po spuštění: Volných bajtů: 10 594 828 288

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 2A2E91BC1B0B73B8FD233BA3FF753A45

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kontrola logu

#14 Příspěvek od cernohous13 »

:arrow: ComboFix odinstalujeme
jdi Start -> Spustit... a zkopíruj ComboFix /Uninstall (pozor, za x je mezera) -> OK

:arrow: Stáhni TempFolderCleaner http://oldtimer.geekstogo.com/TFC.exe
Zavři všechny programy a spusť. Po ukončení akce bude PC restartován.
Pokud ne, restartuj sám.
(čistí Temp složky , nečistí URL, historii, prefetch ani cookies)

:arrow: stáhni program OTC tady: http://oldtimer.geekstogo.com/OTC.exe - spusť ho -> "CleanUp" (smaže dříve použité čističe)

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"

zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace

:arrow: dej mi nový RSIT + popis chování PC (nějaké problémy?)
doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština

:arrow: Nakonec mi dej současný RSIT log
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Guardian23
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 30 lis 2010 09:20

Re: Kontrola logu

#15 Příspěvek od Guardian23 »

Tady je log. Defragmentaci udělám později. Jinak rychlost načítání, zdá se, se o něco snížila. Každopádně budu muset z plochy smazat tu hromadu souborů, zřejmě to má na náběh PC taky vliv.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-11-30 20:41:57
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 11 GB (23%) free of 50 GB
Total RAM: 2047 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:42:02, on 30.11.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Firebird\bin\fbguard.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\LiveZilla\LiveZilla.exe
D:\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
D:\nydecky.cz\xampp\apache\bin\httpd.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Firebird\bin\fbserver.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator.LENKA\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Digsby Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [LiveZilla] "C:\Program Files\LiveZilla\LiveZilla.exe" -minimize
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {b7fe5d70-9aa2-40f1-9c6b-12a255f085e1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/63.27/uploader2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0379200234
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - D:\nydecky.cz\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KoopPdfService - Unknown owner - C:\Program Files\Kooperativa\Services\KoopPDFServer.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: MySQL - MySQL AB - D:\nydecky.cz\xampp\mysql\bin\mysqld.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1.LEN/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 12215 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IcePick_exe.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_LifeExp_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-10-24 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Digsby Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-07-10 1174920]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-07-21 16261632]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"GBB36X Configure"=C:\WINDOWS\system32\JMRaidTool.exe [2006-07-12 356352]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-04-28 282792]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-03-16 47392]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-03-12 119152]
"LiveZilla"=C:\Program Files\LiveZilla\LiveZilla.exe [2010-05-17 2651576]
"iTunesHelper"=D:\iTunes\iTunesHelper.exe [2010-07-21 141608]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]

C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Po spuštění
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe

C:\Documents and Settings\Administrator.LENKA\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2009-07-20 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\bwin\StartbwinPoker.exe"="C:\Program Files\bwin\StartbwinPoker.exe:*:Enabled:StartbwinPoker.exe"
"D:\hl22\HALF LIFE 2\hl2.exe"="D:\hl22\HALF LIFE 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Autodesk\backburner\monitor.exe"="C:\Program Files\Autodesk\backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\backburner\manager.exe"="C:\Program Files\Autodesk\backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\backburner\server.exe"="C:\Program Files\Autodesk\backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Teamspeak2_RC2\server_windows.exe"="C:\Program Files\Teamspeak2_RC2\server_windows.exe:*:Enabled:Server"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\CrosuS\CrosuSApp.exe"="C:\Program Files\CrosuS\CrosuSApp.exe:*:Enabled:Crosus"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"D:\iTunes\iTunes.exe"="D:\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======File associations======

.js - edit -
.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-11-30 20:41:57 ----D---- C:\rsit
2010-11-30 20:26:53 ----D---- C:\Program Files\CCleaner
2010-11-30 20:13:45 ----SHD---- C:\RECYCLER
2010-11-30 19:25:49 ----D---- C:\WINDOWS\temp
2010-11-30 18:55:25 ----RASHD---- C:\cmdcons
2010-11-30 15:31:51 ----D---- C:\WINDOWS\ERDNT
2010-11-30 14:22:38 ----D---- C:\Program Files\HDD Regenerator
2010-11-30 10:14:52 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Malwarebytes
2010-11-30 10:14:43 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-11-30 10:14:41 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-11-30 10:14:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2010-11-30 10:14:41 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-11-29 21:28:16 ----D---- C:\Program Files\trend micro
2010-11-29 19:27:21 ----A---- C:\WINDOWS\system32\drivers\AmdLLD.sys
2010-11-29 19:27:19 ----D---- C:\Program Files\AMD
2010-11-29 18:42:50 ----A---- C:\WINDOWS\system32\drivers\DrvAgent32.sys
2010-11-23 15:29:25 ----D---- C:\Program Files\Microsoft Silverlight
2010-11-05 15:43:18 ----D---- C:\Program Files\CamStudio
2010-10-31 14:48:19 ----A---- C:\WINDOWS\oodcnt.INI
2010-10-31 11:56:42 ----D---- C:\WINDOWS\system32\oodag
2010-10-31 10:00:37 ----D---- C:\Program Files\OO Software

======List of files/folders modified in the last 1 months======

2010-11-30 20:28:38 ----D---- C:\WINDOWS\Minidump
2010-11-30 20:28:38 ----D---- C:\WINDOWS\Debug
2010-11-30 20:28:38 ----D---- C:\WINDOWS
2010-11-30 20:26:53 ----D---- C:\Program Files
2010-11-30 20:25:03 ----SHD---- C:\WINDOWS\Installer
2010-11-30 20:24:28 ----D---- C:\WINDOWS\system32\CatRoot2
2010-11-30 20:15:52 ----SHD---- C:\System Volume Information
2010-11-30 20:15:52 ----D---- C:\WINDOWS\system32\Restore
2010-11-30 20:13:44 ----D---- C:\WINDOWS\system32
2010-11-30 19:35:14 ----D---- C:\WINDOWS\system32\drivers
2010-11-30 19:28:49 ----A---- C:\WINDOWS\system.ini
2010-11-30 19:28:19 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-30 19:26:11 ----D---- C:\WINDOWS\system32\config
2010-11-30 19:25:35 ----SD---- C:\WINDOWS\Tasks
2010-11-30 19:24:26 ----D---- C:\WINDOWS\AppPatch
2010-11-30 19:24:24 ----D---- C:\Program Files\Common Files
2010-11-30 18:55:29 ----RASH---- C:\boot.ini
2010-11-30 17:35:39 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\TEMP
2010-11-30 14:55:28 ----HD---- C:\WINDOWS\inf
2010-11-30 14:51:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2010-11-30 12:29:25 ----A---- C:\WINDOWS\UPGRADE.TXT
2010-11-29 20:54:53 ----A---- C:\WINDOWS\wincmd.ini
2010-11-29 19:27:27 ----A---- C:\Boot.bak
2010-11-26 13:45:45 ----D---- C:\Program Files\Simulace_2009
2010-11-25 18:48:33 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-11-23 15:29:34 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Microsoft
2010-11-22 15:36:13 ----D---- C:\Program Files\Mozilla Firefox
2010-11-22 15:36:02 ----A---- C:\WINDOWS\BRWMARK.INI
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Adobe
2010-11-21 23:27:19 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Adobe
2010-11-19 15:15:07 ----D---- C:\Program Files\bwin
2010-11-18 17:17:27 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Real
2010-11-18 17:17:20 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Real
2010-11-14 21:13:48 ----D---- C:\Documents and Settings\Administrator.LENKA\Data aplikací\Simulace_2009
2010-11-05 15:51:23 ----A---- C:\WINDOWS\NeroDigital.ini
2010-11-03 19:06:16 ----D---- C:\WINDOWS\Microsoft.NET
2010-11-03 17:06:54 ----RSD---- C:\WINDOWS\assembly
2010-11-03 17:05:04 ----D---- C:\Program Files\AEGON Expert 2.0
2010-11-01 11:53:05 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CPC
2010-11-01 11:49:37 ----D---- C:\DATA_CPC
2010-10-31 23:48:20 ----D---- C:\Program Files\CPC
2010-10-31 10:02:17 ----D---- C:\WINDOWS\Help
2010-10-31 09:43:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-07-20 41728]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-11-20 43872]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-02-01 717296]
R1 avfwot;avfwot; C:\WINDOWS\system32\DRIVERS\avfwot.sys [2010-04-28 102856]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2010-04-28 124784]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2010-04-28 28520]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2010-04-28 60936]
R2 BrPar;BrPar; C:\WINDOWS\System32\drivers\BrPar.sys [2000-07-24 19537]
R2 cpuz134;cpuz134; \??\C:\WINDOWS\system32\drivers\cpuz134_x32.sys []
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2004-08-18 88448]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-18 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-18 55936]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\WINDOWS\system32\DRIVERS\AVerBDA3x.sys [2006-12-14 1171456]
R3 avfwim;AvFw Packet Filter Miniport; C:\WINDOWS\system32\DRIVERS\avfwim.sys [2010-04-28 79432]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-05-22 17480]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-18 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-07-24 4353024]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-18 20480]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-12 248192]
S0 cercsr6;cercsr6; C:\WINDOWS\system32\drivers\cercsr6.sys [2004-12-13 39904]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 C-Dilla;C-Dilla; \??\C:\WINDOWS\system32\drivers\CDANT.SYS []
S3 DrvAgent32;DrvAgent32; \??\C:\WINDOWS\system32\Drivers\DrvAgent32.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2010-03-12 30576]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 Pcouffin;Low level access layer for CD devices; C:\WINDOWS\System32\Drivers\Pcouffin.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023k.sys [2002-08-12 11136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirFirewallService;Avira FireWall; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [2010-04-28 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2010-04-28 337064]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-28 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-04-28 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-04-28 405672]
R2 Apache2.2;Apache2.2; D:\nydecky.cz\xampp\apache\bin\httpd.exe [2009-12-20 29416]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-23 77944]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 C-DillaSrv;C-DillaSrv; C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE [2001-01-15 32256]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R2 KoopPdfService;KoopPdfService; C:\Program Files\Kooperativa\Services\KoopPDFServer.exe [2010-07-04 447488]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-03-12 139632]
R2 MySQL;MySQL; D:\nydecky.cz\xampp\mysql\bin\mysqld.exe [2009-12-20 6095504]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2004-05-17 184320]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-11 68096]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-10-22 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-04 30192]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-04 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Odpovědět