Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FB vir, prosím o prohlídku logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

FB vir, prosím o prohlídku logu

#1 Příspěvek od goodoil »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Verunka at 2011-07-31 20:51:01
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 17 GB (6%) free of 297 GB
Total RAM: 2814 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:53:25, on 31.7.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Verunka\AppData\Roaming\dwm.exe
C:\Users\Verunka\AppData\Local\Temp\csrss.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\conime.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TO2SSM\McciTrayApp.exe
C:\Program Files\TO2WCM\McciTrayApp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Windows\update.tray-10-0\svchost.exe
C:\Windows\update.tray-15-0\svchost.exe
C:\Users\Verunka\AppData\Roaming\Microsoft\conhost.exe
C:\Windows\update.tray-12-0\svchost.exe
C:\Windows\update.tray-7-0\svchost.exe
C:\Windows\l1rezerv.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
G:\RSIT.exe
C:\Program Files\trend micro\Verunka.exe
C:\Program Files\Java\jre6\bin\jucheck.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search13.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cz.o2.com/welcome/cz/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search13.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62081
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
F3 - REG:win.ini: load=C:\Users\Verunka\AppData\Local\Temp\csrss.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL (file missing)
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Stylish Profile\enlbrdr.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Lišta Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TO2SSM_McciTrayApp] C:\Program Files\TO2SSM\McciTrayApp.exe
O4 - HKLM\..\Run: [TO2WCM_McciTrayApp] C:\Program Files\TO2WCM\McciTrayApp.exe
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-10-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-15-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico2] C:\Windows\update.tray-12-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico3] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [1233522.exe] "C:\Users\Verunka\AppData\Local\Temp\1233522.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [27608545-loader2.exe] "C:\Windows\Temp\27608545-loader2.exe"
O4 - HKLM\..\Run: [50481234-loader2.exe] "C:\Windows\Temp\50481234-loader2.exe"
O4 - HKLM\..\Run: [489997.exe] "C:\Windows\Temp\489997.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [conhost] C:\Users\Verunka\AppData\Roaming\Microsoft\conhost.exe
O4 - HKLM\..\Run: [1144816.exe] "C:\Windows\TEMP\1144816.exe"
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll (file missing)
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (file missing)
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe (file missing)
O23 - Service: AVG Free WatchDog (avg9wd) - Unknown owner - C:\Program Files\AVG\AVG9\avgwdsvc.exe (file missing)
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Norton Internet Security (NIS) - Unknown owner - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 15372 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://centrum.cz/firefox"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {20a82645-c095-46ed-80e3-08825760534b}:1.1, DTToolbar@toolbarnet.com:1.1.2.0185, toolbar@ask.com:3.9.1.14019, {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.12.1, {6236BA26-C117-4007-928C-DE0716C7FA82}:1.0.2, {6236BA26-C117-4007-928C-DE0716C7FA99}:1.0.1, Cetrumcz@igeared:1.203.023.002, {63414328-3ab4-2c84-6c41-5a473c4b2ff7}:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8"
prefs.js - "keyword.URL" - "http://search.avg.com/route/?d=4b51df23 ... &lng=cs&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{3f963a5b-e555-4543-90e2-c3908898db71}"=C:\Program Files\AVG\AVG9\Firefox
"avg@igeared"=C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared
"Cetrumcz@igeared"=C:\Program Files\CentrumczToolbar\Firefox\Cetrumcz@igeared
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{BBDA0591-3099-440a-AA10-41764D9DB4DB}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\
"{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"=C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeploytk.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
npwachk.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
avg_igeared.xml
Cetrumcz_igeared.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\
DTToolbar@toolbarnet.com
staged-xpis
toolbar@ask.com
{0b38152b-1b20-484d-a11f-5e04a9b0661f}
{20a82645-c095-46ed-80e3-08825760534b}
{6236BA26-C117-4007-928C-DE0716C7FA80}
{6236BA26-C117-4007-928C-DE0716C7FA82}
{6236BA26-C117-4007-928C-DE0716C7FA96}
{6236BA26-C117-4007-928C-DE0716C7FA99}
{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
{EEE6C361-6118-11DC-9C72-001320C79847}

C:\Users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\searchplugins\
askcom.xml
daemon-search.xml
sweetim.xml
web-search.xml
winamp-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\IPSBHO.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
GdfrDUEn Class - C:\Program Files\Stylish Profile\enlbrdr.dll [2010-01-07 185344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-05 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2009-10-19 1345336]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll []
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{D5D47440-0750-463D-BAEF-A47D02414806} - Lišta Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll []
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\18.1.0.37\coIEPlg.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-17 1049896]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2008-09-23 468264]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-10-06 210216]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-08-01 202032]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePDIRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-05 149280]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2009-10-20 111928]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-07-23 13797920]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2010-06-28 74752]
"TO2SSM_McciTrayApp"=C:\Program Files\TO2SSM\McciTrayApp.exe [2009-01-16 1473536]
"TO2WCM_McciTrayApp"=C:\Program Files\TO2WCM\McciTrayApp.exe [2008-01-30 1473536]
"wxpdrv"=C:\Windows\services32.exe [2011-07-17 1154048]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-10-0\svchost.exe [2011-07-17 1154048]
"tray_ico1"=C:\Windows\update.tray-15-0\svchost.exe [2011-07-17 1154048]
"tray_ico2"=C:\Windows\update.tray-12-0\svchost.exe [2011-07-17 1154048]
"tray_ico3"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-17 1154048]
"tray_ico4"= []
"1233522.exe"=C:\Users\Verunka\AppData\Local\Temp\1233522.exe [2011-07-17 232960]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-31 256000]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-31 256000]
"systemup"=C:\Windows\systemup.exe stand []
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-23 232960]
"27608545-loader2.exe"=C:\Windows\Temp\27608545-loader2.exe [2011-07-21 245760]
"50481234-loader2.exe"=C:\Windows\Temp\50481234-loader2.exe [2011-07-22 249344]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe /nogui []
"conhost"=C:\Users\Verunka\AppData\Roaming\Microsoft\conhost.exe [2011-07-31 193536]
"1144816.exe"=C:\Windows\TEMP\1144816.exe [2011-07-31 502272]
"8681893.exe"=C:\Windows\TEMP\8681893.exe [2011-07-31 256000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=~C:\Program Files\MSN Messenger\MsnMsgr.Exe /background []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Google Update"=C:\Users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-04 136176]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-06-15 15141768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"msacm.l3codecp"=l3codecp.acm
"MSVideo8"=VfWWDM32.dll
"msacm.siren"=sirenacm.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FMVC"=fmcodec.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-07-31 20:51:04 ----D---- C:\Program Files\trend micro
2011-07-31 20:51:01 ----D---- C:\rsit
2011-07-25 09:06:17 ----HD---- C:\Windows\update.tray-10-0-lnk
2011-07-25 09:06:17 ----HD---- C:\Windows\update.tray-10-0
2011-07-25 02:34:23 ----D---- C:\Boot
2011-07-25 02:33:45 ----D---- C:\$WINDOWS.~BT
2011-07-25 02:31:46 ----ASH---- C:\WinPEpge.sys
2011-07-24 17:39:02 ----D---- C:\Program Files\Symantec
2011-07-24 17:39:02 ----D---- C:\Program Files\Common Files\Symantec Shared
2011-07-24 17:39:02 ----A---- C:\Windows\system32\drivers\SYMEVENT.SYS
2011-07-24 17:36:14 ----D---- C:\Windows\system32\drivers\NIS
2011-07-24 16:54:01 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-24 16:54:01 ----HD---- C:\Windows\update.tray-7-0
2011-07-24 16:50:02 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-07-24 16:49:59 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-07-24 16:49:50 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-07-24 16:49:48 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-07-24 16:49:45 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-07-24 16:49:41 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-07-24 16:45:59 ----A---- C:\Windows\avastSS.scr
2011-07-24 16:45:57 ----A---- C:\Windows\system32\aswBoot.exe
2011-07-22 09:27:12 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-22 09:27:11 ----A---- C:\Windows\system32\ieui.dll
2011-07-22 09:27:11 ----A---- C:\Windows\system32\iertutil.dll
2011-07-22 09:27:10 ----A---- C:\Windows\system32\jscript9.dll
2011-07-22 09:27:10 ----A---- C:\Windows\system32\jscript.dll
2011-07-22 09:27:09 ----A---- C:\Windows\system32\mshtml.dll
2011-07-22 09:27:08 ----A---- C:\Windows\system32\urlmon.dll
2011-07-22 09:27:08 ----A---- C:\Windows\system32\ieframe.dll
2011-07-21 17:35:06 ----A---- C:\Windows\system32\wininet.dll
2011-07-21 17:35:06 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-21 17:35:06 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-21 17:35:06 ----A---- C:\Windows\system32\msrating.dll
2011-07-21 17:35:06 ----A---- C:\Windows\system32\msls31.dll
2011-07-21 17:35:06 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-21 17:35:05 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-21 17:35:05 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-21 17:35:05 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-21 17:35:05 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\wextract.exe
2011-07-21 17:35:04 ----A---- C:\Windows\system32\webcheck.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\url.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\inseng.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\iexpress.exe
2011-07-21 17:35:04 ----A---- C:\Windows\system32\iesetup.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\iernonce.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-21 17:35:04 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-21 17:35:04 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-21 17:35:04 ----A---- C:\Windows\system32\icardie.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\vbscript.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\occache.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\mshta.exe
2011-07-21 17:35:03 ----A---- C:\Windows\system32\imgutil.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-21 17:35:03 ----A---- C:\Windows\system32\ieakui.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\advpack.dll
2011-07-21 17:35:03 ----A---- C:\Windows\system32\admparse.dll
2011-07-21 17:35:02 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-21 17:35:02 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-21 17:35:02 ----A---- C:\Windows\system32\iepeers.dll
2011-07-21 17:35:02 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-21 17:35:02 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-17 11:00:14 ----A---- C:\Windows\l1rezerv.exe
2011-07-17 11:00:01 ----A---- C:\Windows\ddh_iplist.txt
2011-07-17 10:59:36 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-17 10:59:29 ----A---- C:\Windows\gbot111.exe
2011-07-17 10:59:24 ----D---- C:\Windows\ufa
2011-07-17 10:59:24 ----D---- C:\Windows\rpcminer
2011-07-17 10:59:24 ----D---- C:\Windows\phoenix
2011-07-17 10:59:23 ----A---- C:\Windows\unrar.exe
2011-07-17 10:59:07 ----HD---- C:\Windows\update.2
2011-07-17 10:59:00 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-17 10:58:42 ----A---- C:\Windows\sysdriver32_.exe
2011-07-17 10:58:39 ----HD---- C:\Windows\update.5.0
2011-07-17 10:58:33 ----A---- C:\Windows\iplist.txt
2011-07-17 10:58:27 ----A---- C:\Windows\sysdriver32.exe
2011-07-17 10:57:50 ----A---- C:\Users\Verunka\AppData\Roaming\dwm.exe
2011-07-17 10:57:34 ----A---- C:\Windows\front_ip_list.txt
2011-07-17 10:52:40 ----HD---- C:\Windows\update.tray-15-0-lnk
2011-07-17 10:52:40 ----HD---- C:\Windows\update.tray-15-0
2011-07-17 10:50:47 ----D---- C:\ProgramData\MFAData
2011-07-17 10:41:26 ----D---- C:\Windows\av_ico
2011-07-17 10:38:21 ----HD---- C:\Windows\update.1
2011-07-17 10:37:39 ----HD---- C:\Windows\update.tray-12-0-lnk
2011-07-17 10:37:39 ----HD---- C:\Windows\update.tray-12-0
2011-07-17 10:25:21 ----A---- C:\Windows\winlog-ids.txt
2011-07-17 10:25:21 ----A---- C:\Windows\winlog-dirs.txt
2011-07-17 10:25:15 ----A---- C:\Windows\services32.exe
2011-07-15 06:10:14 ----D---- C:\2458722809cad0023ac9488796
2011-07-13 08:14:24 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-13 08:14:24 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-13 08:14:22 ----A---- C:\Windows\system32\win32k.sys
2011-07-13 08:14:19 ----A---- C:\Windows\system32\kernel32.dll
2011-07-13 08:14:15 ----A---- C:\Windows\system32\winsrv.dll
2011-07-13 08:14:15 ----A---- C:\Windows\system32\csrsrv.dll

======List of files/folders modified in the last 1 month======

2011-07-31 20:52:06 ----D---- C:\Windows
2011-07-31 20:51:26 ----D---- C:\Windows\Temp
2011-07-31 20:51:04 ----RD---- C:\Program Files
2011-07-31 20:50:34 ----D---- C:\Users\Verunka\AppData\Roaming\Skype
2011-07-31 20:48:21 ----D---- C:\Windows\Prefetch
2011-07-31 20:47:50 ----A---- C:\ProgramData\hpqp.ini
2011-07-31 20:47:09 ----SD---- C:\Users\Verunka\AppData\Roaming\Microsoft
2011-07-31 20:46:51 ----D---- C:\Windows\system32\Tasks
2011-07-25 09:25:20 ----SHD---- C:\System Volume Information
2011-07-25 09:07:07 ----HD---- C:\ProgramData
2011-07-24 17:39:02 ----D---- C:\Windows\system32\drivers
2011-07-24 17:39:02 ----D---- C:\Program Files\Common Files
2011-07-24 16:49:17 ----D---- C:\Windows\winsxs
2011-07-24 16:47:29 ----SHD---- C:\Windows\Installer
2011-07-24 16:45:57 ----D---- C:\Windows\System32
2011-07-22 09:43:41 ----D---- C:\Program Files\Internet Explorer
2011-07-22 09:27:57 ----D---- C:\Windows\system32\catroot
2011-07-22 09:27:56 ----D---- C:\Windows\system32\catroot2
2011-07-21 20:03:02 ----D---- C:\Windows\rescache
2011-07-21 19:53:33 ----D---- C:\ProgramData\CentrumczToolbar
2011-07-21 18:01:07 ----D---- C:\Windows\system32\config
2011-07-21 18:01:02 ----D---- C:\Windows\Tasks
2011-07-21 18:01:02 ----D---- C:\Windows\system32\Msdtc
2011-07-21 18:01:02 ----D---- C:\Windows\inf
2011-07-21 18:01:02 ----D---- C:\Program Files\Opera
2011-07-21 18:01:00 ----D---- C:\Windows\registration
2011-07-21 17:37:35 ----D---- C:\Windows\system32\sk-SK
2011-07-21 17:37:34 ----D---- C:\Windows\system32\cs-CZ
2011-07-21 17:37:33 ----RD---- C:\Windows\Offline Web Pages
2011-07-21 17:37:33 ----D---- C:\Windows\system32\wbem
2011-07-21 17:37:33 ----D---- C:\Windows\system32\migration
2011-07-21 17:37:33 ----D---- C:\Windows\system32\en-US
2011-07-21 17:37:33 ----D---- C:\Windows\PolicyDefinitions
2011-07-21 17:37:31 ----SD---- C:\Windows\Downloaded Program Files
2011-07-21 17:35:30 ----D---- C:\Windows\Logs
2011-07-19 19:05:08 ----D---- C:\Program Files\Mozilla Firefox
2011-07-17 11:03:22 ----D---- C:\Program Files\Microsoft Office
2011-07-17 10:59:36 ----D---- C:\Windows\system32\drivers\etc
2011-07-17 10:39:48 ----D---- C:\Windows\system32\drivers\Avg
2011-07-17 10:38:20 ----SHD---- C:\$RECYCLE.BIN
2011-07-15 06:10:20 ----A---- C:\Windows\system32\mrt.exe
2011-07-15 06:10:11 ----D---- C:\ProgramData\Microsoft Help
2011-07-14 14:19:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-14 10:25:27 ----RD---- C:\Program Files\Skype
2011-07-14 10:25:23 ----D---- C:\ProgramData\Skype
2011-07-14 10:24:27 ----D---- C:\ProgramData\Easybits GO
2011-07-14 10:24:09 ----D---- C:\Users\Verunka\AppData\Roaming\go
2011-07-03 20:48:41 ----D---- C:\Windows\Microsoft.NET
2011-07-03 20:48:40 ----RSD---- C:\Windows\assembly
2011-07-03 20:07:09 ----RSD---- C:\Windows\Fonts

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-25 691696]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\NIS\1201000.025\SYMDS.SYS [2010-06-13 339504]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS [2010-07-29 666672]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-07-19 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-06-02 29584]
R1 AvgTdiX;AVG Free Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2011-05-05 243152]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2010-08-13 371248]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1201000.025\SRTSPX.SYS [2010-07-29 50096]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver; C:\Windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS [2010-07-13 331312]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-11-16 50704]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-18 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-06-05 222208]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-11-01 208896]
R3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-03-29 20096]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-01-29 1042464]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-07-23 9791072]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-04-25 14848]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-09-19 61952]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2011-07-24 126512]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-17 199344]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-11-01 661504]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S1 BHDrvx86;BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx86.sys []
S1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVix86.sys []
S1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\NIS\1201000.025\Ironx86.SYS [2010-06-27 134704]
S3 ad5hsms2;ad5hsms2; C:\Windows\system32\drivers\ad5hsms2.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-03-29 21248]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\NAVENG.SYS []
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\NAVEX15.SYS []
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\system32\drivers\NIS\1201000.025\SRTSP.SYS [2010-07-29 489008]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2007-10-15 303104]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-20 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-07-23 211488]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-10-06 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-09-15 241734]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-31 348672]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-31 502272]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-31 256000]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-17 1154048]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-18 386560]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 NIS;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe /s NIS /m C:\Program Files\Norton Internet Security\Engine\18.1.0.37\diMaster.dll /prefetch:1 []
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, prosím o prohlídku logu

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com :arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost 2 a potvrte enterem
  • Utilita provede svou cinnost a da log - ten sem vlozte
  • Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#3 Příspěvek od goodoil »

RogueKiller V5.2.9 [07/31/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Verunka [Admin rights]
Mode: Remove -- Date : 07/31/2011 21:58:02

Bad processes: 0

Registry Entries: 21
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\Windows\services32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1233522.exe ("C:\Users\Verunka\AppData\Local\Temp\1233522.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\Windows\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\Windows\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("C:\Windows\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\Windows\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 27608545-loader2.exe ("C:\Windows\Temp\27608545-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 50481234-loader2.exe ("C:\Windows\Temp\50481234-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : conhost (C:\Users\Verunka\AppData\Roaming\Microsoft\conhost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 1144816.exe ("C:\Windows\TEMP\1144816.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 8681893.exe ("C:\Windows\TEMP\8681893.exe") -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (explorer.exe,C:\Users\Verunka\AppData\Roaming\dwm.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\Verunka\AppData\Local\Temp\csrss.exe) -> DELETED
[SUSP PATH] HKUS\.DEFAULT[...]\Winlogon : Shell (explorer.exe,C:\Windows\system32\config\systemprofile\AppData\Roaming\dwm.exe) -> DELETED
[HJ] {20D04FE0-3AEA-1069-A2D8-08002B30309D}\ 1: -> REPLACED (0)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]


Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#4 Příspěvek od goodoil »

RogueKiller V5.2.9 [07/31/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Verunka [Admin rights]
Mode: HOSTSFix -- Date : 07/31/2011 21:58:33

Bad processes: 0

HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#5 Příspěvek od goodoil »

RogueKiller V5.2.9 [07/31/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Verunka [Admin rights]
Mode: ProxyFix -- Date : 07/31/2011 21:59:00

Bad processes: 0

Registry Entries: 1
[PROXY FF] z438glbl.default\ 127.0.0.1:62081 -> DELETED

Finished : << RKreport[4].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, prosím o prohlídku logu

#6 Příspěvek od vyosek »

:arrow: Aplikujte exeHelper by Raktor PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#7 Příspěvek od goodoil »

ComboFix 11-07-31.04 - Verunka 01.08.2011 17:01:59.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2814.1581 [GMT 2:00]
Spuštěný z: c:\users\Verunka\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Verunka\AppData\Roaming\dwm.exe
c:\users\Verunka\AppData\Roaming\Microsoft\conhost.exe
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\gbot111.exe
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer
c:\windows\rpcminer.rar
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\services32.exe
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-10-0\svchost.exe
c:\windows\update.tray-12-0\svchost.exe
c:\windows\update.tray-15-0\svchost.exe
c:\windows\update.tray-7-0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srvbtcclient
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_usnjsvc
-------\Service_wxpdrivers
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-01 do 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 15:10 . 2011-08-01 15:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 14:52 . 2011-08-01 14:52 -------- d-----w- c:\programdata\Norton
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- c:\program files\trend micro
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- C:\rsit
2011-07-25 07:06 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-10-0
2011-07-25 07:06 . 2011-07-25 07:06 -------- d--h--w- c:\windows\update.tray-10-0-lnk
2011-07-25 00:34 . 2011-07-25 00:34 -------- d-----w- C:\Boot
2011-07-25 00:33 . 2011-07-25 00:33 -------- d-----w- C:\$WINDOWS.~BT
2011-07-25 00:31 . 2011-07-25 00:31 268435456 --sha-w- C:\WinPEpge.sys
2011-07-24 15:39 . 2011-07-25 07:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-07-24 15:39 . 2011-07-24 15:39 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-24 15:39 . 2011-07-24 15:39 -------- d-----w- c:\program files\Symantec
2011-07-24 15:36 . 2011-07-24 15:36 -------- d-----w- c:\windows\system32\drivers\NIS
2011-07-24 14:54 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-24 14:54 . 2011-07-24 14:54 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-24 14:50 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 14:49 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 14:49 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 14:49 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 14:49 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 14:49 . 2011-07-04 11:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 14:45 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 14:45 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-22 07:27 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-22 07:27 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-07-22 07:27 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-21 15:03 . 2011-07-21 15:03 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_63305.bat
2011-07-20 16:05 . 2011-07-20 16:05 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_65208.bat
2011-07-17 08:59 . 2011-07-17 08:59 -------- d-----w- c:\windows\ufa
2011-07-17 08:59 . 2011-07-17 17:28 246272 ----a-w- c:\windows\unrar.exe
2011-07-17 08:52 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-15-0
2011-07-17 08:52 . 2011-07-17 08:52 -------- d--h--w- c:\windows\update.tray-15-0-lnk
2011-07-17 08:50 . 2011-07-17 08:50 -------- d-----w- c:\programdata\MFAData
2011-07-17 08:41 . 2011-07-25 07:09 -------- d-----w- c:\windows\av_ico
2011-07-17 08:37 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-12-0
2011-07-17 08:37 . 2011-07-17 08:37 -------- d--h--w- c:\windows\update.tray-12-0-lnk
2011-07-15 04:10 . 2011-07-15 04:12 -------- d-----w- C:\2458722809cad0023ac9488796
2011-07-13 06:14 . 2011-04-21 13:55 508416 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 06:14 . 2009-06-17 13:23 30208 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 06:14 . 2011-06-02 13:34 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 06:14 . 2011-04-20 15:55 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 06:14 . 2011-04-20 15:50 49152 ----a-w- c:\windows\system32\csrsrv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-05 15:24 . 2010-01-16 15:45 243152 ----a-w- c:\windows\system32\drivers\avgtdix.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-10-19 187192]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-01-07 06:51 185344 ----a-w- c:\program files\Stylish Profile\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-19 15:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-06 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-23 13797920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-06-28 74752]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2009-01-16 1473536]
"TO2WCM_McciTrayApp"="c:\program files\TO2WCM\McciTrayApp.exe" [2008-01-30 1473536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3983374240-1131744942-3270535697-1000]
"EnableNotificationsRef"=dword:00000001
.
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [x]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVix86.sys [x]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS [2010-06-27 134704]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [x]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-25 691696]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS [2010-06-13 339504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS [2010-07-29 666672]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-19 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2011-05-05 243152]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS [2010-07-13 331312]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job
- c:\users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-04 14:20]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job
- c:\users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-04 14:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.cz.o2.com/welcome/cz/index.html
uDefault_Search_URL = hxxp://search13.net/
mStart Page = hxxp://home.sweetim.com
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
TCP: DhcpNameServer = 10.0.0.138
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b51df23&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=cs&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: aTube Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: Express Tab: {6236BA26-C117-4007-928C-DE0716C7FA82} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
FF - Ext: FBFan: {6236BA26-C117-4007-928C-DE0716C7FA99} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - c:\program files\AVAST Software\Avast\ashShell.dll
HKCU-Run-MsnMsgr - ~c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico0 - c:\windows\update.tray-10-0\svchost.exe
HKLM-Run-tray_ico1 - c:\windows\update.tray-15-0\svchost.exe
HKLM-Run-tray_ico2 - c:\windows\update.tray-12-0\svchost.exe
HKLM-Run-tray_ico3 - c:\windows\update.tray-7-0\svchost.exe
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-avast - c:\program files\AVAST Software\Avast\avastUI.exe
AddRemove-Jazz Jackrabbit (DOSBox 0.74 emulation) - c:\users\Verunka\Desktop\Uninstal.exe
AddRemove-NIS - c:\program files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\18.1.0.37\InstStub.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-01 17:19
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.1.0.37\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Celkový čas: 2011-08-01 17:23:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-01 15:23
.
Před spuštěním: Volných bajtů: 15 218 421 760
Po spuštění: Volných bajtů: 16 339 468 288
.
- - End Of File - - 4CA330A27EB4AD6CFD3E917D16C49CF2

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, prosím o prohlídku logu

#8 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\windows\update.tray-10-0
    c:\windows\update.tray-10-0-lnk
    c:\windows\update.tray-7-0
    c:\windows\update.tray-7-0-lnk
    c:\windows\ufa
    c:\windows\update.tray-15-0
    c:\windows\update.tray-15-0-lnk
    c:\windows\av_ico
    c:\windows\update.tray-12-0
    c:\windows\update.tray-12-0-lnk
    c:\program files\Ask.com
    c:\program files\Winamp Toolbar
    c:\program files\SweetIM
    c:\program files\Stylish Profile
    C:\Program Files\DAEMON Tools Toolbar
    
    File::
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job
    
    Collect::
    c:\windows\unrar.exe
    
    Registry::[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{00000000-6E41-4FD3-8538-502F5495E5FC}"=-
    "{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"=-
    "{EEE6C35D-6118-11DC-9C72-001320C79847}"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
    "{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
    [-HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
    [-HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
    [-HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
    [-HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
    [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
    [-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UpdateLBPShortCut"=-
    "UpdatePSTShortCut"=-
    "UCam_Menu"=-
    "UpdateP2GoShortCut"=-
    "UpdatePDIRShortCut"=-
    "SunJavaUpdateSched"=-
    "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    "WinampAgent"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "FirewallOverride"=dword:00000000
    "DisableThumbnailCache"=dword:00000000
    
    DDS::
    uStart Page = hxxp://www.cz.o2.com/welcome/cz/index.html
    uDefault_Search_URL = hxxp://search13.net/
    mStart Page = hxxp://home.sweetim.com
    uSearchAssistant = hxxp://search13.net/
    uCustomizeSearch = hxxp://search13.net/
    IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
    Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
    
    Firefox::
    Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
    FF - ProfilePath - c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/sli ... ie7&query=
    FF - prefs.js: browser.search.selectedEngine - Ask.com
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b51df23 ... &lng=cs&q=
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: aTube Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
    FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#9 Příspěvek od goodoil »

ComboFix 11-07-31.04 - Verunka 01.08.2011 18:57:14.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2814.1341 [GMT 2:00]
Spuštěný z: c:\users\Verunka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Verunka\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-01 do 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 17:03 . 2011-08-01 17:05 -------- d-----w- c:\users\Verunka\AppData\Local\temp
2011-08-01 17:03 . 2011-08-01 17:03 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 14:52 . 2011-08-01 14:52 -------- d-----w- c:\programdata\Norton
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- c:\program files\trend micro
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- C:\rsit
2011-07-25 07:06 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-10-0
2011-07-25 07:06 . 2011-07-25 07:06 -------- d--h--w- c:\windows\update.tray-10-0-lnk
2011-07-25 00:34 . 2011-07-25 00:34 -------- d-----w- C:\Boot
2011-07-25 00:33 . 2011-07-25 00:33 -------- d-----w- C:\$WINDOWS.~BT
2011-07-25 00:31 . 2011-07-25 00:31 268435456 --sha-w- C:\WinPEpge.sys
2011-07-24 15:39 . 2011-07-25 07:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-07-24 15:39 . 2011-07-24 15:39 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-24 15:39 . 2011-07-24 15:39 -------- d-----w- c:\program files\Symantec
2011-07-24 15:36 . 2011-07-24 15:36 -------- d-----w- c:\windows\system32\drivers\NIS
2011-07-24 14:54 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-24 14:54 . 2011-07-24 14:54 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-24 14:50 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 14:49 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 14:49 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 14:49 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 14:49 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 14:49 . 2011-07-04 11:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 14:45 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 14:45 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-22 07:27 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-22 07:27 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-07-22 07:27 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-21 15:03 . 2011-07-21 15:03 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_63305.bat
2011-07-20 16:05 . 2011-07-20 16:05 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_65208.bat
2011-07-17 08:59 . 2011-07-17 08:59 -------- d-----w- c:\windows\ufa
2011-07-17 08:59 . 2011-07-17 17:28 246272 ----a-w- c:\windows\unrar.exe
2011-07-17 08:52 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-15-0
2011-07-17 08:52 . 2011-07-17 08:52 -------- d--h--w- c:\windows\update.tray-15-0-lnk
2011-07-17 08:50 . 2011-07-17 08:50 -------- d-----w- c:\programdata\MFAData
2011-07-17 08:41 . 2011-07-25 07:09 -------- d-----w- c:\windows\av_ico
2011-07-17 08:37 . 2011-08-01 15:09 -------- d--h--w- c:\windows\update.tray-12-0
2011-07-17 08:37 . 2011-07-17 08:37 -------- d--h--w- c:\windows\update.tray-12-0-lnk
2011-07-15 04:10 . 2011-07-15 04:12 -------- d-----w- C:\2458722809cad0023ac9488796
2011-07-13 06:14 . 2011-04-21 13:55 508416 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 06:14 . 2009-06-17 13:23 30208 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 06:14 . 2011-06-02 13:34 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 06:14 . 2011-04-20 15:55 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 06:14 . 2011-04-20 15:50 49152 ----a-w- c:\windows\system32\csrsrv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-05 15:24 . 2010-01-16 15:45 243152 ----a-w- c:\windows\system32\drivers\avgtdix.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-10-19 187192]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-01-07 06:51 185344 ----a-w- c:\program files\Stylish Profile\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 21:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-19 15:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-06 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-05 149280]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-23 13797920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-06-28 74752]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2009-01-16 1473536]
"TO2WCM_McciTrayApp"="c:\program files\TO2WCM\McciTrayApp.exe" [2008-01-30 1473536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3983374240-1131744942-3270535697-1000]
"EnableNotificationsRef"=dword:00000001
.
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [x]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVix86.sys [x]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS [2010-06-27 134704]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [x]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-25 691696]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS [2010-06-13 339504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS [2010-07-29 666672]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-19 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2011-05-05 243152]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS [2010-07-13 331312]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job
- c:\users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-04 14:20]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job
- c:\users\Verunka\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-04 14:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.cz.o2.com/welcome/cz/index.html
uDefault_Search_URL = hxxp://search13.net/
mStart Page = hxxp://home.sweetim.com
uSearchAssistant = hxxp://search13.net/
uCustomizeSearch = hxxp://search13.net/
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
TCP: DhcpNameServer = 10.0.0.138
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b51df23&v=6.010.006.004&i=23&tp=ab&iy=&ychte=us&lng=cs&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: aTube Toolbar: toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: Express Tab: {6236BA26-C117-4007-928C-DE0716C7FA82} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
FF - Ext: FBFan: {6236BA26-C117-4007-928C-DE0716C7FA99} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-01 19:05
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.1.0.37\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\System32\lpksetup.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conime.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Celkový čas: 2011-08-01 19:12:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-01 17:11
ComboFix2.txt 2011-08-01 15:23
.
Před spuštěním: Volných bajtů: 16 268 169 216
Po spuštění: Volných bajtů: 16 131 792 896
.
- - End Of File - - 8A5410F57313B7C34F74AE0A84835B75

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, prosím o prohlídku logu

#10 Příspěvek od vyosek »

Cf nejak neprovedlo co melo :o

Opakujte prosim postup v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#11 Příspěvek od goodoil »

Zopakoval jsem předchozí krok, myslím, že jsem tam nevložil ten skript správně. Pokud ani tentokrát neprovedl CF co měl, tak to zkusím v nouzovém režimu, jak jste radil. Poslední log:


ComboFix 11-07-31.04 - Verunka 01.08.2011 19:40:49.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.2814.1790 [GMT 2:00]
Spuštěný z: c:\users\Verunka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Verunka\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job"
.
file zipped: c:\windows\unrar.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_b856.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\CentrumczToolbar\IEToolbar.dll
c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\map.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24.ico
c:\program files\DAEMON Tools Toolbar\Resources\soft24_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\program files\Stylish Profile
c:\program files\Stylish Profile\ct.htm
c:\program files\Stylish Profile\enlbrdr.dll
c:\program files\Stylish Profile\hoticon.ico
c:\program files\Stylish Profile\tomapi.js
c:\program files\Stylish Profile\tommain.js
c:\program files\Stylish Profile\uninstall.exe
c:\program files\SweetIM
c:\program files\SweetIM\Messenger\default.xml
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\program files\SweetIM\Messenger\mgAIMAuto.dll
c:\program files\SweetIM\Messenger\mgAIMMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgArchive.dll
c:\program files\SweetIM\Messenger\mgcommon.dll
c:\program files\SweetIM\Messenger\mgcommunication.dll
c:\program files\SweetIM\Messenger\mgconfig.dll
c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
c:\program files\SweetIM\Messenger\mghooking.dll
c:\program files\SweetIM\Messenger\mgICQAuto.dll
c:\program files\SweetIM\Messenger\mgICQMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgIEPlayer.dll
c:\program files\SweetIM\Messenger\mglogger.dll
c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
c:\program files\SweetIM\Messenger\mgMsnAuto.dll
c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgsimcommon.dll
c:\program files\SweetIM\Messenger\mgSweetIM.dll
c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
c:\program files\SweetIM\Messenger\mgYahooAuto.dll
c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
c:\program files\SweetIM\Messenger\msvcp71.dll
c:\program files\SweetIM\Messenger\msvcr71.dll
c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
c:\program files\SweetIM\Messenger\resources\images\GamesButton.png
c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
c:\program files\SweetIM\Messenger\SweetIM.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\ClearHist.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\conf\logger.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\default.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\mgcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgconfig.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mghooking.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mglogger.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\about.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\affid.dat
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\basis.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dating.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\find.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\games.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\glitter.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\help.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\highlight.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\locales.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_21x18.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\music.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\news.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\options.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\photos.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\shopping.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\version.txt
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-search.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png
c:\program files\Winamp Toolbar
c:\program files\Winamp Toolbar\apopup.dll
c:\program files\Winamp Toolbar\install.log
c:\program files\Winamp Toolbar\msvcr71.dll
c:\program files\Winamp Toolbar\uninstall.exe
c:\program files\Winamp Toolbar\winamptb.dll
c:\program files\Winamp Toolbar\winampTbServer.exe
c:\program files\Winamp Toolbar\winamptbServerPS.dll
c:\program files\Winamp Toolbar\xprt5.dll
c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\IWinampPlayer.xpt
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\IWinampUninstallObserver.xpt
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampUninstallObserver.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\chrome.manifest
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\chrome\winamptoolbar.jar
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\install.rdf
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF\MANIFEST.MF
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF\ZIGBERT.RSA
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\META-INF\ZIGBERT.SF
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\DTToolbar@toolbarnet.com\install.rdf
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\datastore\cache.sqlite
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\defaults.js.bak
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\defaults\preferences\defaults.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome.manifest
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\about.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\about.xul
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\cache.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\constants.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\core.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\custom-command-listener.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\events.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\feeds.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\json.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\lifecycle.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\listeners.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\locale.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\logger.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\network.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\observer.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\options.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\options.xul
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\preferences.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\prefetch.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\ss-popup-bindings.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\suggestions.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\update.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\updateRdf.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\utilities.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\webframe-bindings.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\webframe-manager.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\widget-controller.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\widget-popup.xul
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\content\widgets.js
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\abc.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\amazon_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\as.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\ask_16x16.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\ask_32x32.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\ask_browser_ff_chrome.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\asklogo.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\bbc_news.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\beppe_grillo.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\bg.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\bild.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\blogs.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\business.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\close.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\cnn_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\corriere_della_sera.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\dictionary.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\el_mundo.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\email_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\expansion.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\facebook_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\folha.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\ft.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\ftd.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\g1.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\games_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\gazzetta_dello_sport.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\globe_18x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\glove_logo_atubecatcher.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\gripper.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\highlight_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\highlighter_off.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\highlighter_on.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\hola.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\chevron.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_film1_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_history_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_news_ru_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_nu_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_radiodigital_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_sports_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_sportsru_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icon_vk_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\icons_business_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\images.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\kicker.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-de.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-en.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-es.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-fr.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-it.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-nl.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-pt.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\labels-ru.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\laposte.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\lemonde.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\lequipe.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\libero_it.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-BR.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-DE.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-ES.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-EU.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-FR.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-IT.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-NL.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-RU.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-UK.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\links-US.properties
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\logo_32x32.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\magnify_search.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\magnify_search_grey_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\maps.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\marmiton.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\mtv.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\news.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\oglobo.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\orkut.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\preferences.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_de.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_es.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_fr.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_it.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_nl.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pl.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_pt.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ask_ru.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_cobrand.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_current_site.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_de.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_es.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_fr.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_grey_73x24.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_it.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_nl.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_pl.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_pt.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\search_ru.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\searchbox.xml
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\shopping.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\sports.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\stocks.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\supportedsites.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\terra.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\titlebar_bg.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\toolbar.css
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\toolbar.xul
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\tv.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\tv_movie_de.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\uol.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\video_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\weather.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\weather_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\web.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\web_de.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\wordoftheday_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\youtube_16x.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\skin\zoomall.png
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Mon-01-Nov-2010-09-59-08-GMT\ff-config.zip
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Tue-19-Jul-2011-17-05-21-GMT\ff-config.zip
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\chrome\temp\ff-config.Wed-05-Jan-2011-11-06-28-GMT\ff-config.zip
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\install.rdf
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1288605546587.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1288605583277.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1288605595669.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1294225586857.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1294225607048.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1296150133319.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1296150133994.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\logs\asktb-log-1311095120558.html
c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\extensions\toolbar@ask.com\searchplugins\askcom.xml
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_defender_start.ico
c:\windows\av_ico\ico_norton_start.ico
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3983374240-1131744942-3270535697-1000UA.job
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-10-0-lnk
c:\windows\update.tray-10-0-lnk\svchost.exe
c:\windows\update.tray-10-0
c:\windows\update.tray-12-0-lnk
c:\windows\update.tray-12-0-lnk\svchost.exe
c:\windows\update.tray-12-0
c:\windows\update.tray-15-0-lnk
c:\windows\update.tray-15-0-lnk\svchost.exe
c:\windows\update.tray-15-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0-lnk\svchost.exe
c:\windows\update.tray-7-0
.
.

goodoil
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 31 črc 2011 19:43

Re: FB vir, prosím o prohlídku logu

#12 Příspěvek od goodoil »

((((((((((((((((((((((((( Soubory vytvořené od 2011-07-01 do 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 17:50 . 2011-08-01 17:52 -------- d-----w- c:\users\Verunka\AppData\Local\temp
2011-08-01 17:50 . 2011-08-01 17:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 16:55 . 2011-08-01 17:37 -------- d-----w- C:\32788R22FWJFW
2011-08-01 14:52 . 2011-08-01 14:52 -------- d-----w- c:\programdata\Norton
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- c:\program files\trend micro
2011-07-31 18:51 . 2011-07-31 18:53 -------- d-----w- C:\rsit
2011-07-25 00:34 . 2011-07-25 00:34 -------- d-----w- C:\Boot
2011-07-25 00:33 . 2011-07-25 00:33 -------- d-----w- C:\$WINDOWS.~BT
2011-07-25 00:31 . 2011-07-25 00:31 268435456 --sha-w- C:\WinPEpge.sys
2011-07-24 15:39 . 2011-07-25 07:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-07-24 15:39 . 2011-07-24 15:39 126512 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-24 15:39 . 2011-07-24 15:39 -------- d-----w- c:\program files\Symantec
2011-07-24 15:36 . 2011-07-24 15:36 -------- d-----w- c:\windows\system32\drivers\NIS
2011-07-24 14:50 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 14:49 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 14:49 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 14:49 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 14:49 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 14:49 . 2011-07-04 11:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 14:45 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 14:45 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-22 07:27 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-22 07:27 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-07-22 07:27 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-21 15:03 . 2011-07-21 15:03 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_63305.bat
2011-07-20 16:05 . 2011-07-20 16:05 141 ----a-w- c:\users\Verunka\AppData\Roaming\Microsoft\gb_65208.bat
2011-07-17 08:50 . 2011-07-17 08:50 -------- d-----w- c:\programdata\MFAData
2011-07-15 04:10 . 2011-07-15 04:12 -------- d-----w- C:\2458722809cad0023ac9488796
2011-07-13 06:14 . 2011-04-21 13:55 508416 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-13 06:14 . 2009-06-17 13:23 30208 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-13 06:14 . 2011-06-02 13:34 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-07-13 06:14 . 2011-04-20 15:55 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-13 06:14 . 2011-04-20 15:50 49152 ----a-w- c:\windows\system32\csrsrv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-05 15:24 . 2010-01-16 15:45 243152 ----a-w- c:\windows\system32\drivers\avgtdix.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-23 13797920]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2009-01-16 1473536]
"TO2WCM_McciTrayApp"="c:\program files\TO2WCM\McciTrayApp.exe" [2008-01-30 1473536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3983374240-1131744942-3270535697-1000]
"EnableNotificationsRef"=dword:00000001
.
R1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx86.sys [x]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVix86.sys [x]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1201000.025\Ironx86.SYS [2010-06-27 134704]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe [x]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [x]
R3 CFcatchme;CFcatchme;c:\users\Verunka\AppData\Local\Temp\CFcatchme.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-08-25 691696]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1201000.025\SYMDS.SYS [2010-06-13 339504]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1201000.025\SYMEFA.SYS [2010-07-29 666672]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-19 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2011-05-05 243152]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\NIS\1201000.025\SYMTDIV.SYS [2010-07-13 331312]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-11-16 50704]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-05-09 43040]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search13.net/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\users\Verunka\AppData\Roaming\Mozilla\Firefox\Profiles\z438glbl.default\
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Express Tab: {6236BA26-C117-4007-928C-DE0716C7FA82} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA82}
FF - Ext: FBFan: {6236BA26-C117-4007-928C-DE0716C7FA99} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
URLSearchHooks-{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-Stylish Profile - c:\program files\Stylish Profile\uninstall.exe
AddRemove-Winamp Toolbar - c:\program files\Winamp Toolbar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-01 19:52
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.1.0.37\diMaster.dll\" /prefetch:1"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\System32\lpksetup.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conime.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Celkový čas: 2011-08-01 19:57:37 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-01 17:57
ComboFix2.txt 2011-08-01 17:12
ComboFix3.txt 2011-08-01 15:23
.
Před spuštěním: Volných bajtů: 16 791 953 408
Po spuštění: Volných bajtů: 16 765 403 136
.
- - End Of File - - 9EE50EFD45DE5D87FC8D382B03AD4DFB
Nahr nˇ probŘhlo ŁspŘçnŘ

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: FB vir, prosím o prohlídku logu

#13 Příspěvek od vyosek »

Uz je to OK, jak se chova PC - antiviry zatim nereste - jsou poskozene, bude treba s nimi udelat poradek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět