Stránka 1 z 2

spomalený NB aj po reštarte

Napsal: 10 zář 2011 14:02
od sima707
Logfile of random's system information tool 1.09 (written by random/random)
Run by Sima at 2011-09-10 15:01:32
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 51 GB (17%) free of 296 GB
Total RAM: 3068 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:01:42, on 10. 9. 2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Advanced Wheel Mouse\wh_exec.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Windows\System32\rundll32.exe
C:\Windows\svcdotnet\svcdotnet.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Users\Sima\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Sima\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Sima\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Sima\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Sima\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Winamp\winamp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Sima\Downloads\RSIT.exe
C:\Program Files\trend micro\Sima.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.uniba.sk/?cosign-filter-a ... D.server12
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [TVAgent] "C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [WheelMouse] C:\ADVANC~1\wh_exec.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [Module Loader] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe -StartUpRun
O4 - HKLM\..\Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor
O4 - HKLM\..\Run: [svcdotnet] C:\Windows\svcdotnet\svcdotnet.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [FileHunter Check for updates] C:\Users\Sima\AppData\Roaming\FileHunter\update.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (file missing) (HKCU)
O9 - Extra button: QIP Infium - {4599502F-4427-4C23-AC58-F4AB721FBCF7} - C:\Program Files\QIP Infium\infium.exe (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe

--
End of file - 16688 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000UA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default

prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "DTToolbar@toolbarnet.com:1.0.8.0552, {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.2.26, fdm_ffext@freedownloadmanager.org:1.3.4, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, bkmrksync@nokia.com:1.0.0.736, {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="

"otis@digitalpersona.com"=C:\Program Files\DigitalPersona\Bin\FirefoxExt\
"{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}"=C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\
"m3ffxtbr@mywebsearch.com"=C:\Program Files\MyWebSearch\bar\1.bin
"bkmrksync@nokia.com"=C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
aboutCertError.js
aboutPrivateBrowsing.js
aboutRights.js
aboutRobots.js
aboutSessionRestore.js
AskSearch.js
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsHandlerService.js
nsHelperAppDlg.js
nsIQTScriptablePlugin.xpt
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPostUpdateWin.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js

C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml

C:\Users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\
DTToolbar@toolbarnet.com
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\searchplugins\
daemon-search.xml
icqplugin-1.xml
icqplugin.xml
mywebsearch.xml
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-27 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-07-24 1348904]
"DVDAgent"=C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-11-28 1148200]
"TSMAgent"=C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"=C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-12-25 189736]
"UCam_Menu"=C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe [2008-11-14 218408]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-11-18 914224]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-11-26 210216]
"DpAgent"=C:\Program Files\DigitalPersona\Bin\dpagent.exe [2008-12-10 842816]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-10-10 206128]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-10-30 210216]
"UpdatePDIRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-12-08 432432]
"TVAgent"=C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe [2009-02-09 206120]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-10-26 450659]
"WheelMouse"=C:\ADVANC~1\wh_exec.exe [2007-11-10 98304]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-18 421888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe [2010-02-18 241789]
"Module Loader"=C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe [2007-07-23 57344]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-10-23 202024]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2010-08-20 33120]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
"Google Update"=C:\Users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-06 136176]
"FileHunter Check for updates"=C:\Users\Sima\AppData\Roaming\FileHunter\update.exe [2011-07-17 810096]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-07-29 17361032]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"msacm.siren"=sirenacm.dll
"vidc.VP60"=C:\Windows\system32\vp6vfw.dll
"vidc.VP61"=C:\Windows\system32\vp6vfw.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-09-02 12:36:21 ----A---- C:\ProgramData\svcdotnet.txt
2011-08-25 20:50:29 ----A---- C:\Windows\system32\tzres.dll
2011-08-23 09:04:17 ----D---- C:\Program Files\PDF Password Remover v3.0
2011-08-22 18:16:15 ----D---- C:\Users\Sima\AppData\Roaming\FileHunter
2011-08-11 03:14:22 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-11 03:14:20 ----A---- C:\Windows\system32\ieui.dll
2011-08-11 03:14:20 ----A---- C:\Windows\system32\iertutil.dll
2011-08-11 03:14:19 ----A---- C:\Windows\system32\jscript9.dll
2011-08-11 03:14:19 ----A---- C:\Windows\system32\jscript.dll
2011-08-11 03:14:18 ----A---- C:\Windows\system32\wininet.dll
2011-08-11 03:14:18 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-11 03:14:17 ----A---- C:\Windows\system32\urlmon.dll
2011-08-11 03:14:17 ----A---- C:\Windows\system32\url.dll
2011-08-11 03:14:17 ----A---- C:\Windows\system32\ieframe.dll
2011-08-11 03:14:15 ----A---- C:\Windows\system32\mshtml.dll

======List of files/folders modified in the last 1 month======

2011-09-10 15:01:40 ----A---- C:\ProgramData\HPWALog.txt
2011-09-10 15:01:36 ----D---- C:\Program Files\trend micro
2011-09-10 14:48:33 ----SHD---- C:\System Volume Information
2011-09-10 14:45:32 ----D---- C:\Users\Sima\AppData\Roaming\Skype
2011-09-10 14:39:38 ----D---- C:\Windows\temp
2011-09-10 14:31:43 ----RD---- C:\Program Files
2011-09-10 14:30:50 ----D---- C:\ProgramData
2011-09-10 14:30:43 ----D---- C:\Windows\System32
2011-09-10 14:30:43 ----D---- C:\Windows\inf
2011-09-10 14:30:43 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-09-09 16:31:44 ----A---- C:\Windows\NeroDigital.ini
2011-09-08 22:41:44 ----D---- C:\Windows\Prefetch
2011-09-08 14:11:52 ----D---- C:\Users\Sima\AppData\Roaming\BSplayer
2011-09-08 03:00:58 ----D---- C:\Windows\winsxs
2011-09-08 03:00:56 ----D---- C:\Windows\system32\catroot
2011-09-04 22:04:18 ----D---- C:\Users\Sima\AppData\Roaming\vlc
2011-09-03 23:05:28 ----D---- C:\Users\Sima\AppData\Roaming\ICQ
2011-09-03 20:17:30 ----D---- C:\Program Files\ICQ7.5
2011-09-02 12:43:39 ----D---- C:\Windows\rescache
2011-09-02 12:36:17 ----D---- C:\Windows
2011-08-28 13:59:55 ----SHD---- C:\Windows\Installer
2011-08-28 13:59:16 ----D---- C:\Windows\system32\Tasks
2011-08-28 13:59:12 ----RD---- C:\Program Files\Skype
2011-08-28 13:59:00 ----D---- C:\ProgramData\Skype
2011-08-25 20:55:09 ----D---- C:\Windows\system32\sk-SK
2011-08-25 20:55:09 ----D---- C:\Windows\system32\cs-CZ
2011-08-23 20:52:15 ----D---- C:\Windows\system32\catroot2
2011-08-23 11:10:50 ----RSD---- C:\Windows\assembly
2011-08-23 11:10:50 ----D---- C:\Windows\Microsoft.NET
2011-08-19 08:07:13 ----D---- C:\Users\Sima\AppData\Roaming\Mozilla
2011-08-11 03:32:13 ----D---- C:\Windows\system32\migration
2011-08-11 03:32:13 ----D---- C:\Windows\system32\drivers
2011-08-11 03:32:13 ----D---- C:\Program Files\Windows Mail
2011-08-11 03:32:13 ----D---- C:\Program Files\Internet Explorer
2011-08-11 03:16:05 ----D---- C:\ProgramData\Microsoft Help
2011-08-11 03:07:29 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2008-03-27 24424]
R0 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-05 436792]
R1 Ext2fs;Ext2fs; C:\Windows\system32\DRIVERS\ext2fs.sys [2008-09-25 189888]
R1 IfsMount;IfsMount; C:\Windows\system32\DRIVERS\ifsmount.sys [2008-08-28 60352]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKslba557e3e;MpKslba557e3e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\MpKslba557e3e.sys [2011-09-10 28752]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-03-15 56268]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/09 03:24:48]; \??\C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl [2008-11-28 87536]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-16 278728]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-16 25416]
R3 Accelerometer;HP Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [2008-03-27 34664]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-12-31 4172288]
R3 AVerAF15;HP DVB-T TV Tuner; C:\Windows\System32\Drivers\AVerAF15.sys [2008-07-04 280448]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-09 1331192]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-06-17 30208]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-06-23 80424]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2008-06-23 81960]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-06-23 16168]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-10-23 107360]
R3 ksaud;Creative USB Audio Driver; C:\Windows\system32\drivers\ksaud.sys [2010-07-30 1255168]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-08-06 124928]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2008-10-26 391168]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-07-24 201264]
R3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 whfltr2k;WheelMouse USB Lower Filter Driver; C:\Windows\system32\DRIVERS\whfltr2k.sys [2007-01-26 6784]
R3 WinUSB;WinUSB Service; C:\Windows\system32\DRIVERS\WinUSB.sys [2009-04-11 31616]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S1 MpKsl9f3ad83a;MpKsl9f3ad83a; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{209FDBBB-791C-4477-AA3A-DB7BFFE39026}\MpKsl9f3ad83a.sys []
S3 a0xetjmk;a0xetjmk; C:\Windows\system32\drivers\a0xetjmk.sys []
S3 azdlk3a9;azdlk3a9; C:\Windows\system32\drivers\azdlk3a9.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-04-21 508416]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmb.sys [2008-05-02 17536]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbo.sys [2008-05-02 20864]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2008-05-02 8064]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]
S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2009-04-11 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-02 8064]
S3 vaxscsi;vaxscsi; C:\Windows\System32\Drivers\vaxscsi.sys [2010-09-03 223128]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe [2008-06-27 77824]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2008-12-31 724992]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2010-02-12 286720]
R2 DpHost;@C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128; C:\Program Files\DigitalPersona\Bin\DpHostW.exe [2008-12-10 322624]
R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2008-03-18 19456]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2009-08-05 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\system32\PnkBstrB.exe [2009-08-05 107832]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-12-17 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-09-15 241734]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe [2008-10-26 237657]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TVCapSvc;TV Background Capture Service (TVBCS); C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-02-09 296320]
R2 TVSched;TV Task Scheduler (TVTS); C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-02-09 116096]
R2 vfsFPService;Validity Fingerprint Service; C:\Windows\system32\vfsFPService.exe [2008-11-18 599344]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-10-23 223232]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-10-23 382248]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-07-04 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-07-04 79360]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-07-31 654848]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 Battery Optimizer;Battery Optimizer; C:\Program Files\ReviverSoft\Battery Optimizer\BatteryOptimizerService.exe [2010-09-14 103296]

-----------------EOF-----------------

Re: spomalený NB aj po reštarte

Napsal: 10 zář 2011 16:50
od chodnik74
Dobrý podvečer :welcome:

Máme tam pěknou zoo :evil: Takže jdeme na to :James008:

:arrow: Stáhněte program RogueKiller
  • Spuste program
  • Stiskněte klávesu 2 a enter
  • Objeví se vám log a ten sem vložte
  • Stějně tak opakujte s volbou 3 a 4 a vložte logy

Program nepoužívejte bez doporučení Rádce a pozorně se řiďte následujících pokynu,protože program netoleruje chyby a může dojít k úplnému poškození systému!!
  • :arrow: Stáhneme si Combofix Obrázek
  • Program uložíme nejlépe na Plochu
  • Vypneme všechny rezidentní štíty.Jak antiviru,tak antispywaru a firewallu
  • Vypneme všechny běžící aplikace (ICQ,prohlížeč,programy) a necháme pouze Combofix
  • Spustíme Combofix.exe s administrátorským oprávněním
    U Windows XP se přihlásíme pod účtem správce
    Ve Windows 7 a Vista klikněte pravým tlačítkem myši na Combofix.exe a dejte ,,Spustit jako správce,,)
  • Hned po startu programu na vás vyskočí licenční podmínky,tak potvrdíme tlačítkemANO
  • Pokud vám Combofix nabídne instalaci Konzoly pro zotavení,tak souhlaste a nechte nainstalovat(zde je potřeba aktivní připojení na internet)
  • Pokračujte dle pokynů programu a během skenování na nic neklikejte,na pc nepracujte(ICQ,jiné aplikace,internet..).Nechte počítač v klidu.
  • Celý sken tvá mezi 5-15 min,ale pokud je v PC hodně havěti,tak se čas může lišit.
  • Po skončení skenování(případném restartu počítače) se vám zobrazí log z Combofixu,který mi vložte sem(Kdyby se log nezobrazil,tak jej najdete zde: C:\ComboFix.txt
  • (Pokud si nevíte rady s kterýmkoliv z výše uvedených kroků,tak se ptejte nebo mrkněte na detailnější návod včetně obrázků http://www.bleepingcomputer.com/combofi ... t-combofix )

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 00:54
od sima707
Zdravím : ) a ďakujem za pomoc vopred : )
voľba 2:
RogueKiller V5.3.4 [08/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Sima [Admin rights]
Mode: Remove -- Date : 09/11/2011 01:48:57

Bad processes: 0

Registry Entries: 3
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

Particular Files / Folders:

HOSTS File:
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt

voľba 3
RogueKiller V5.3.4 [08/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Sima [Admin rights]
Mode: HOSTSFix -- Date : 09/11/2011 01:50:17

Bad processes: 0

HOSTS File:
127.0.0.1 localhost


Resetted HOSTS:
127.0.0.1 localhost

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt



voľba 4
RogueKiller V5.3.4 [08/30/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Sima [Admin rights]
Mode: ProxyFix -- Date : 09/11/2011 01:50:34

Bad processes: 0

Registry Entries: 0

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt


a log z combofixu doplním za moment :)

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 01:42
od sima707
combo fix mi vyhadzoval často acces denied a všetko spojené s týmto programom trvalo nejak prehnane dlho
ale vypla som všetky štíty, programy a spustila to ako správca tak nvm prečo mi toto vyhadzoval
ale tak tu je len log ktorý mi vytváralo takmer hodinu a bez reštartu

ComboFix 11-09-10.03 - Sima . 09. 2011 2:02.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3068.1783 [GMT 2:00]
Running from: c:\users\Sima\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Family Keylogger 4
c:\programdata\Microsoft\Windows\Start Menu\Programs\Family Keylogger 4\Family Keylogger.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Family Keylogger 4\Help.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Family Keylogger 4\Quick Start.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Family Keylogger 4\Uninstall.lnk
c:\windows\system32\no
c:\windows\system32\no\DPCrProv.dll.mui
c:\windows\system32\no\DPSDApi.dll.mui
c:\windows\system32\sfklg.dll
c:\windows\system32\sfklgcp.exe
c:\windows\system32\SV
c:\windows\system32\SV\DPCrProv.dll.mui
c:\windows\system32\SV\DPSDApi.dll.mui
.
.
((((((((((((((((((((((((( Files Created from 2011-08-11 to 2011-09-11 )))))))))))))))))))))))))))))))
.
.
2072-04-03 11:13 . 2008-03-21 12:46 607296 ------w- c:\program files\Microsoft Games\Age of Empires III\deformerdllyD.dll
2011-09-11 00:18 . 2011-09-11 00:18 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-09-11 00:18 . 2011-09-11 00:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-10 12:22 . 2011-09-10 12:22 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\MpKslba557e3e.sys
2011-09-10 12:04 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\mpengine.dll
2011-09-09 11:53 . 2010-11-30 09:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEBF318B-9569-44A0-ABEF-A2FA949FCBCD}\gapaengine.dll
2011-09-02 10:36 . 2011-09-02 10:36 -------- d--h--w- c:\windows\svcdotnet
2011-08-25 18:50 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-23 07:04 . 2011-08-23 07:04 -------- d-----w- c:\program files\PDF Password Remover v3.0
2011-08-13 11:18 . 2010-11-30 09:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-23 07:25 . 2011-05-24 13:08 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-12 02:44 . 2011-06-23 10:36 7152464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-22 02:54 . 2011-08-11 01:14 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-22 02:48 . 2011-08-11 01:14 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-07-22 02:44 . 2011-08-11 01:14 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-13 03:39 . 2011-07-28 01:01 6881616 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-06 15:31 . 2011-08-10 11:34 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-04 11:58 . 2009-07-30 22:11 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2011-07-04 11:58 . 2009-07-30 22:11 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-20 08:54 . 2011-08-10 11:33 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-20 08:54 . 2011-08-10 11:33 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 20:13 . 2011-08-10 11:33 913296 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-17 16:03 . 2011-08-10 11:34 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-06-17 13:31 . 2011-08-10 11:33 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-07-29 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904]
"DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-11-28 1148200]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"UCam_Menu"="c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2008-11-14 218408]
"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-11-18 914224]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-11-26 210216]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-12-10 842816]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-10-26 450659]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-11-10 98304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe" [2010-02-18 241789]
"Module Loader"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"Creative SB Monitoring Utility"="sbavmon.dll" [2010-07-29 103936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1569211908-327731248-3284688791-1000]
"EnableNotificationsRef"=dword:00000001
.
R1 MpKsl9f3ad83a;MpKsl9f3ad83a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{209FDBBB-791C-4477-AA3A-DB7BFFE39026}\MpKsl9f3ad83a.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-07-04 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-07-04 79360]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2010-07-30 1255168]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2010-09-03 223128]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Battery Optimizer;Battery Optimizer;c:\program files\ReviverSoft\Battery Optimizer\BatteryOptimizerService.exe [2010-09-14 103296]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-02-05 436792]
S1 Ext2fs;Ext2fs;c:\windows\system32\DRIVERS\ext2fs.sys [2008-09-25 189888]
S1 IfsMount;IfsMount;c:\windows\system32\DRIVERS\ifsmount.sys [2008-08-28 60352]
S1 MpKslba557e3e;MpKslba557e3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\MpKslba557e3e.sys [2011-09-10 28752]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/09 03:24];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-11-28 16:04 87536]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe [2008-06-27 77824]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-12-17 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-02-09 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-02-09 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-11-18 599344]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys [2008-07-04 280448]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-10-23 107360]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLBA557E3E
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000Core.job
- c:\users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-06 18:17]
.
2011-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000UA.job
- c:\users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-06 18:17]
.
.
------- Supplementary Scan -------
.
uStart Page = https://login.uniba.sk/?cosign-filter-a ... D.server12
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=sk_sk&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.100.252
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.9&q=
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-11 02:20
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(7856)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\advanced wheel mouse\wh_hook.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\BtwNamespaceExt.dll
c:\windows\system32\BtwNeLib.dll
c:\windows\system32\btwapi.dll
c:\windows\system32\btosif.dll
c:\windows\system32\btwpimif.dll
c:\windows\system32\btrez.dll
c:\program files\Common Files\Nero\Lib\MediaLibraryNSE.dll
c:\program files\Common Files\Nero\DSFilter\NeVideo.ax
c:\program files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll
c:\program files\Common Files\Nero\DSFilter\NeFLVSplitter.ax
c:\program files\Common Files\Nero\DSFilter\NeMP4Splitter.ax
c:\program files\Common Files\Nero\DSFilter\NeSplitter.ax
c:\program files\Common Files\Nero\DSFilter\NeOggSplitter.ax
c:\program files\Common Files\Nero\DSFilter\NeSubpicture.ax
c:\program files\Common Files\Nero\DSFilter\NeResize.ax
c:\program files\Common Files\Nero\DSFilter\NeVideoHD.ax
.
Completion time: 2011-09-11 02:40:26
ComboFix-quarantined-files.txt 2011-09-11 00:40
ComboFix2.txt 2011-06-23 11:25
.
Pre-Run: 53 994 799 104 bytes free
Post-Run: 54 797 361 152 bytes free
.
- - End Of File - - C96B9F5EA38C4FEB5A9A0FCF0D1A5593

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 11:14
od chodnik74
Super,odinstalujte Easybits,ICQ Toolbar a všechny ostatní toolbary,které nepoužíváte..


:arrow: Otevřeme si Poznámkový blok Obrázek
  • (stiskneme klávesovou kombinaci WIN+R a napíšeme ,,notepad,, bez úvozovek a dáme enter)
  • Vložíme do něj následující script:

    Kód: Vybrat vše

    
    KillAll::
    
    Folder::
    c:\windows\svcdotnet
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=-
    "ehTray.exe"=-
    "DAEMON Tools Lite"=-
    "PC Suite Tray"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NokiaMServer"=-
    "StartCCC"=-
    "DVDAgent"=-
    "UCam_Menu"=-
    "SmartMenu"=-
    "UpdateLBPShortCut"=-
    "UpdatePSTShortCut"=-
    "UpdateP2GoShortCut"=-
    "UpdatePDIRShortCut"=-
    "SunJavaUpdateSched"=-
    "HP Software Update"=-
    "NeroFilterCheck"=-
    "NBKeyScan"=-
    "SysTrayApp"=-
    "QuickTime Task"=-
    "Adobe Reader Speed Launcher"=-
    "Adobe ARM"=-
    
    DDS::
    uStart Page = https://login.uniba.sk/?cosign-filter-a ... D.server12
    uDefault_Search_URL = hxxp://search.qip.ru
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://search.qip.ru/ie
    uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
    
    Firefox::
    FF - ProfilePath - c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\
    FF - prefs.js: browser.search.selectedEngine - ICQ Search
    FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
    FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... r=1.1.9&q=
    FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    FF - Ext: DAEMON Tools Toolbar: DTToolbar@toolbarnet.com - %profile%\extensions\DTToolbar@toolbarnet.com
    FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
    
    Reboot::
    
  • Soubor uložíme na Plochu jako CFScript.txt
  • Poté tento soubor uchopíme levým tlačítkem myši a přetáhneme na ikonu Combofixu a upustíme

    Obrázek
  • Poté Combofix provede všechny operace a udělá nový log,který sem vložte

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 12:20
od sima707
cez ovladaci panel - programy a súčasti mi žiadne toolbary už nenašlo....ja som ICQ toolbar už dávno odinštalovala, tak nvm prečo ho tam vidíte...nvte poradiť nejaký dobrý unistall program?

ComboFix 11-09-11.01 - Sima . 09. 2011 12:35:43.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.3068.1511 [GMT 2:00]
Running from: c:\users\Sima\Desktop\ComboFix.exe
Command switches used :: c:\users\Sima\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components\ITB_History.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\user.js
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\icqtoolbar.jar
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\install.rdf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\manifest.mf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.rsa
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.sf
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.gif
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.src
c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components\ITB_History.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\prefs.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\user.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome.manifest
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.xul
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\autocomplete.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\exitobserver.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\globals.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\highlight.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.xul
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgLarge.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgSmall.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonBlue.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonGreen.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\searchLogo.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\localfileupdate.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\menu-button.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_bg.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_cz.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_de.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_en.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_es.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_fr.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_he.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_it.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_ru.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_sk.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_tr.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_uk.html
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.xul
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsegamesxml.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsemenuxml.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.xul
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\prefutils.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\search.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\splitter.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\statistics.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\tabcontext.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\utilities.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\voucher.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\zoom.js
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\icq_locale.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb_options.dtd
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\options.properties
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\about.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\abt.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ain.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ang.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\default.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dis.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dropmarker.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\hide.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\icons.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\logo_small.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_r.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_y.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\options.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\peoplesearch.css
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg_y.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\install.rdf
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\manifest.mf
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.rsa
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.sf
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.src
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.xpt
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\about.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AboutWindow.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\accept.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\AddRadioStation.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\as.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_buy.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_download.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_feedback.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_forum.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_home.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astro_lite.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroburn_site.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\astroLite_16.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\az.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\b1.png
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_files.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_image.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\burn_imgs.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\BurnImage.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\buy.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond000.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond001.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond003.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond004.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond005.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond006.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond007.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond008.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond009.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond010.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond011.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond019.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond020.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond021.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond022.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond023.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond024.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond025.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond026.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond037.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond038.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond039.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond040.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond041.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond046.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond048.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond050.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond051.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond052.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond053.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond054.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond055.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond056.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond057.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond058.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond059.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond060.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond061.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond062.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond063.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond064.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond065.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond066.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond067.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond068.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond069.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond075.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond076.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond077.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond078.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond079.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond080.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond084.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond085.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond086.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond087.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond088.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond089.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond090.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond091.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond092.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond093.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond094.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond095.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond108.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond109.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond110.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond111.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond112.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond113.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond120.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond121.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond122.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond126.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond127.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond128.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond129.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond130.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond131.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond132.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond133.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond134.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond135.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond136.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond137.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond138.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond140.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond141.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond142.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond143.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond148.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond149.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond152.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond154.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond155.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond156.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\cond157.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Config.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\d2.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\daemon_search_site.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_disabled.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_enabled.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dot_on_over.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\download.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ds.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dsearch.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt-home.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_about.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_buy.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_download.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_faq.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_feedback.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_forum.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_line.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_lite.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_manual.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dt_pro.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\DTPro.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt16.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\dtt32.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Dwnl.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\emulation.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\faq.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\favicon.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\features.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\feedback.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\forum.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrix.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixCristals.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixDownload.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixPlayOnline.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameCentrixTop.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameS.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\games_search_SA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GameSA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gct16.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\gd.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\genre.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\globe.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\GrabImage.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hb.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\help.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\hide.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\home.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\image_search_SA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageS.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ImageSA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\ip.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lang.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\lingvo.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\m.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_disable.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mail_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_disable.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mailc_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\manual.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\map.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioConfig.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRadioStation.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuRSCur.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\MenuTr.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\mount_n_drive.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\next_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\none_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\noW.gif
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\op.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\play_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\pragma.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prev_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\prod.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Radio.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBg.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioBgMask.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDisp_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioDown_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioE.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioG.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioL.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLDotMask.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeft.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLeftMask.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioLM.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioM.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioN.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioR.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRM.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioRU.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioVolume_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RadioW.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbcheck.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rbtxt.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\refresh_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Rss1.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssA1.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssClose.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssL.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\rssOpen.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\RssRefresh.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\s2.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\show.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_lr.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\size_rl.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\skins.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\soft24_SA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\spt.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\stop_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\style.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\SupportRequest.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\time.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\timer.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\TitleIcon.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\toolbar.xml
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\trans.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_disable.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Trash_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\u.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\unmount-all.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_back.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_dott_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_mute_check.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\vol_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wb.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtClose_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_down.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_m.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wBtText_under.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Weather_m42.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\Weather_m43.bmp
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_resources.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\web_search_SA.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebS.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\WebSa.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi0.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi1.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi10.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi11.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi12.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi13.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi14.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi2.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi3.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi4.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi5.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi6.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi7.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi8.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\components\Resources\wi9.ico
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\chrome.manifest
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\chrome\dttoolbar.jar
c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\extensions\DTToolbar@toolbarnet.com\install.rdf
c:\windows\svcdotnet
c:\windows\svcdotnet\QuickStart.html
c:\windows\svcdotnet\svcdotnet.dll
c:\windows\svcdotnet\svcdotnet.exe
c:\windows\svcdotnet\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-11 to 2011-09-11 )))))))))))))))))))))))))))))))
.
.
2072-04-03 11:13 . 2008-03-21 12:46 607296 ------w- c:\program files\Microsoft Games\Age of Empires III\deformerdllyD.dll
2011-09-11 10:44 . 2011-09-11 10:54 -------- d-----w- c:\users\Sima\AppData\Local\temp
2011-09-11 10:44 . 2011-09-11 10:44 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-09-11 10:44 . 2011-09-11 10:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-10 12:22 . 2011-09-10 12:22 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\MpKslba557e3e.sys
2011-09-10 12:04 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\mpengine.dll
2011-09-09 11:53 . 2010-11-30 09:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AEBF318B-9569-44A0-ABEF-A2FA949FCBCD}\gapaengine.dll
2011-08-25 18:50 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-23 07:04 . 2011-08-23 07:04 -------- d-----w- c:\program files\PDF Password Remover v3.0
2011-08-13 11:18 . 2010-11-30 09:43 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-23 07:25 . 2011-05-24 13:08 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-12 02:44 . 2011-06-23 10:36 7152464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-22 02:54 . 2011-08-11 01:14 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-07-22 02:48 . 2011-08-11 01:14 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-07-22 02:44 . 2011-08-11 01:14 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-13 03:39 . 2011-07-28 01:01 6881616 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-06 15:31 . 2011-08-10 11:34 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-04 11:58 . 2009-07-30 22:11 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2011-07-04 11:58 . 2009-07-30 22:11 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-20 08:54 . 2011-08-10 11:33 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-20 08:54 . 2011-08-10 11:33 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 20:13 . 2011-08-10 11:33 913296 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-17 16:03 . 2011-08-10 11:34 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-06-17 13:31 . 2011-08-10 11:33 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-07-29 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904]
"TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-12-25 189736]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-12-10 842816]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-10-10 206128]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-12-08 432432]
"TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-02-09 206120]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-11-10 98304]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi Surround 5.1 Pro\Volume Panel\VolPanlu.exe" [2010-02-18 241789]
"Module Loader"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"Creative SB Monitoring Utility"="sbavmon.dll" [2010-07-29 103936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1569211908-327731248-3284688791-1000]
"EnableNotificationsRef"=dword:00000001
.
R1 MpKsl9f3ad83a;MpKsl9f3ad83a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{209FDBBB-791C-4477-AA3A-DB7BFFE39026}\MpKsl9f3ad83a.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-07-04 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-07-04 79360]
R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2010-07-30 1255168]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Kontrola siete od spoločnosti Microsoft;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2010-09-03 223128]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Battery Optimizer;Battery Optimizer;c:\program files\ReviverSoft\Battery Optimizer\BatteryOptimizerService.exe [2010-09-14 103296]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-02-05 436792]
S1 Ext2fs;Ext2fs;c:\windows\system32\DRIVERS\ext2fs.sys [2008-09-25 189888]
S1 IfsMount;IfsMount;c:\windows\system32\DRIVERS\ifsmount.sys [2008-08-28 60352]
S1 MpKslba557e3e;MpKslba557e3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A454ACCC-CC17-464F-83BE-45E3DBA643C8}\MpKslba557e3e.sys [2011-09-10 28752]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/07/09 03:24];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-11-28 16:04 87536]
S2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe [2008-06-27 77824]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-12-17 365952]
S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-02-09 296320]
S2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-02-09 116096]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-11-18 599344]
S3 AVerAF15;HP DVB-T TV Tuner;c:\windows\system32\Drivers\AVerAF15.sys [2008-07-04 280448]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-11-19 222512]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-09-04 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-10-23 107360]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000Core.job
- c:\users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-06 18:17]
.
2011-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1569211908-327731248-3284688791-1000UA.job
- c:\users\Sima\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-06 18:17]
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.100.252
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Sima\AppData\Roaming\Mozilla\Firefox\Profiles\f2agc8p8.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 12:20
od sima707
- - - - ORPHANS REMOVED - - - -
.
AddRemove-FKL 4 - c:\windows\svcdotnet\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-11 12:54
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3652)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\advanced wheel mouse\wh_hook.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.

------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\DigitalPersona\Bin\DpHostW.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehRecvr.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\system32\conime.exe
c:\advanced wheel mouse\wh_exec.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\Shared\hpqToaster.exe
.
**************************************************************************
.
Completion time: 2011-09-11 12:58:53 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-11 10:58
ComboFix2.txt 2011-09-11 00:40
ComboFix3.txt 2011-06-23 11:25
.
Pre-Run: 54 833 934 336 bytes free
Post-Run: 54 676 430 848 bytes free
.
- - End Of File - - 5CF881C35CC34A090430213B0B209D38

Re: spomalený NB aj po reštarte

Napsal: 11 zář 2011 12:27
od chodnik74
:arrow: Doporučuji Revo Uninstaller :) je k dostání zdarma...


:arrow: Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění a zkopírujte a vložte sem následujíci text: Combofix /Uninstall a dejte enter



:arrow: ObrázekT-Cleaner
  • Spustíme,zmáčkneme klávesu A a potvrdíme ENTER(některé antiviry mohou detekovat utilitu jako vir-jedá se o falešný poplach,proto IGNOROVAT nebo dočasně vypnout antivir )
  • po použití T-Cleaner smažte ;-)


:arrow: Obrázek TFC
  • Stáhneme a spustíme program
  • Klikneme na Start a potvrdíme OK
  • Program začne uklízet,poté restartuje pc
  • po použití program smažte

:arrow: Malwarebytes' Anti-Malware Obrázek
  • Stáhneme,nainstalujeme a spustíme(pokud si nevíte rady jak,klikněte ZDE)
  • Vybereme Úplná kontrola a klikneme na tlačítko ProhledatObrázek
  • Program provede kontrolu počítače a na konci se vám objeví hláska,že bylo skenování dokončeno,tak potvrdíme tlačítkem OK
  • Objeví se vám log,který mi sem vložte
  • NIC NEMAZAT!!Program mívá občas falešné detekce,takže mazat budeme až po konzultaci :twisted:

Re: spomalený NB aj po reštarte

Napsal: 12 zář 2011 11:45
od sima707
:)

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Verzia databázy: 7694

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

11. 9. 2011 22:02:39
mbam-log-2011-09-11 (22-02-31).txt

Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 426202
Uplynutý čas: 2 hod, 58 min, 14 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 2
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 4

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken.

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\Users\Sima\downloads\spfkl4-setup-03.exe (Spyware.Keylogger) -> No action taken.
c:\Users\Sima\downloads\a-pdf.restrictions.remover.1.6.9.exe (PUP.FileHunter) -> No action taken.
c:\Users\Sima\downloads\actualspy.exe (Application.ActualSpy) -> No action taken.
c:\Users\Sima\downloads\keygen.a-pdf.restrictions.remover.1.6.9.exe (PUP.FileHunter) -> No action taken.

Re: spomalený NB aj po reštarte

Napsal: 12 zář 2011 16:12
od chodnik74
Nalezené položky dejte smazat..

Odinstalujte Malwarebytes nebo si zanechte na skenování 1x 14 dní :James008:


Údržba PC:

1)Čištění dočasných složek + neplatné registry
:arrow: ObrázekCcleaner
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • ČISTIČ
    Windows zde necháme vše jak je (pokud používáme IE,tak odškrkneme jeho položky) a zaškrkneme položky Start Menu zástupci a Zástupci na ploše
    Aplikace - necháme jak je,ale pokud používáme nějaký prohlížeč (Google chrome,Firefox,Opera..) tak odškrkneme jeho položky
    >Stiskeneme tlačítko Analyzovat a poté Spustit Cleaner
  • Registry
    >Stiskneme tlačítko Hledej problémy,program začne hledat neplatné registry..podé zvolíme Opravit vybrané problémy..
    >Program se zeptá,zda chceme vytvořit zálohu registrů,zvolíme ano a uložíme si někde zálohu(kdyby byli po opravení registru s něčím problémy,tak zálohu
    obnovíme tak,že spustíme uloženou zálohu a potvrdíme ano),dále zvolíme Opravit všechny problémy a Zavřít
    >opakujte dokud nebude registr bez problémů
  • Program používáme 1x 14dní (záleží na používání pc,můžeme i jednou týdně)
2)Defragmentace disku
:arrow: ObrázekDefraggler
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • Vybereme disk ( C:,D:..prostě který používáme)
  • Pokud je ve sloupci Fragmentace více než 5% dejte Defragmentovat
  • Proveďte se všemi používanými disky
  • Provádíme 1x za měsíc
3)Aktualizace programů
:arrow: ObrázekFileHippo.com Update Checker
  • Stáhneme a nainstalujeme program(Při instalaci odškrkneme volbu Run at Startup )
  • Spustíme program
  • Program vyhledá nainstalované programy v PC a zjistí dostupné aktualizace
  • Poté se vám otevře internetová stránka,kde budou nabídnuté aplikace k aktualizování
    >X Updates Detected..to jsou dostupné aktualizace..
    > klikneme na zelenou šipečku a stáhneme program,poté nainstalujeme jeho aktuální verzi
    > :!: X Beta Updates Detected..tyto aktualizace nestahujte,jedná se o betaverze,které jsou ve vývoji a jsou nestabilní :)
  • Provádíme 1x za 14 dní nebo jednou za měsíc

:arrow: Jak se chová počítač? + nový RSIT :)

Re: spomalený NB aj po reštarte

Napsal: 21 zář 2011 20:51
od sima707
prepáčte, že len teraz, ale mala som teraz zápis v škole a tieto prvé týždne školy som nestíhala tak len teraz
ten mallware som vypla takže sa mi to nedalo odstrániť už...spustila som to znova a teraz je takýto ten log....tak mám všetko zmazať??
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Verzia databázy: 7757

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

21. 9. 2011 21:28:46
log.txt

Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 432630
Uplynutý čas: 6 hod, 19 min, 31 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 2
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> No action taken.

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RF6TT02.exe (PUP.FileHunter) -> No action taken.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RJZIENH.exe (Spyware.Keylogger) -> No action taken.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RU9S214.exe (Application.ActualSpy) -> No action taken.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RXMOENT.exe (PUP.FileHunter) -> No action taken.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$ROYM98Y\keygen\keygen.exe (RiskWare.Tool.CK) -> No action taken.


ĎAKUJEM :)

Re: spomalený NB aj po reštarte

Napsal: 21 zář 2011 20:53
od chodnik74
Ano,všechno dejte smazat a vysypte koš :)

Re: spomalený NB aj po reštarte

Napsal: 21 zář 2011 22:00
od sima707
už je to v poriadku?

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Verzia databázy: 7757

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

21. 9. 2011 22:52:50
mbam-log-2011-09-21 (22-52-50).txt

Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 432630
Uplynutý čas: 6 hod, 19 min, 31 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 2
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registračné kľúče:
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registračných dát:
(Škodlivé položky neboli zistené)

Infikované priečinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RF6TT02.exe (PUP.FileHunter) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RJZIENH.exe (Spyware.Keylogger) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RU9S214.exe (Application.ActualSpy) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$RXMOENT.exe (PUP.FileHunter) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-1569211908-327731248-3284688791-1000\$ROYM98Y\keygen\keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

Re: spomalený NB aj po reštarte

Napsal: 22 zář 2011 05:02
od chodnik74
:arrow: Stáhneme si na Plochu program OTMObrázek
  • Spustíme soubor OTM.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Spustí se nám program OTM a do levého okna ,,Paste Instructions for Items to be Moved,, vložíme následující skript a stiskneme tlačítko MoveIt

    Kód: Vybrat vše

    
    :Files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    c:\$RECYCLE.BIN\
    
    :Reg
    [-HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}]
    [-HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}]
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [ResetHosts]
    
    
  • Po restartu pc se vám objeví log z OTM,ten mi sem prosím vložte..

Re: spomalený NB aj po reštarte

Napsal: 26 zář 2011 19:20
od sima707
prešlo asi 10 min a ten log mi vôbec po reštarte nevyhodilo.....čo s tým teraz?
ten NB je stále nejaký retardovaný