oukej tu je log
ComboFix 12-03-31.02 - chlopi . 04. 2012 16:56:41.3.2 - x86 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.3071.2558 [GMT 2:00]
Running from: c:\users\chlopi\Desktop\ComboFix.exe
Command switches used :: c:\users\chlopi\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\program files\Softonic-Eng7\prxtbSof2.dll"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001Core.job"
"c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001UA.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Trojan Remover
c:\program files\TrojanHunter 5.3
c:\program files\uTorrentBar
c:\users\chlopi\%APPDATA%
c:\users\chlopi\AppData\Local\Facebook\Update
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_et.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fa.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fi.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fil.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fr.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_gu.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hi.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hr.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hu.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_id.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_is.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_it.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_iw.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ja.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_kn.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ko.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lt.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lv.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ml.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_mr.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ms.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_nl.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_no.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_or.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pl.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-BR.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-PT.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ro.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ru.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sk.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sl.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sr.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sv.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ta.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_te.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_th.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_tr.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_uk.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ur.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_vi.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-CN.dll
c:\users\chlopi\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-TW.dll
c:\users\chlopi\AppData\Local\Facebook\Update\FacebookUpdate.exe
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\Activate Antivirus Protection 2012.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\Antivirus Protection 2012.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\Help Antivirus Protection 2012.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection 2012\How to Activate Antivirus Protection 2012.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus Protection\Activate Antivirus Protection.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus Protection\Antivirus Protection.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AntiVirus Protection\Help Antivirus Protection.lnk
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antivirus Protection\How to Activate Antivirus Protection.lnk
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitAutoCompleteSearch.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\ConduitAutoCompleteSearch.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko10.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko19.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko5.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko6.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko7.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko8.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko9.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\alertSettingsComponent.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\appContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\fbAlert.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\getAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\postAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\toolbarContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\defaults\unsharedAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\chrome.manifest
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\chrome\softonic-eng7.jar
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\manifest.mf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\zigbert.rsa
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\META-INF\zigbert.sf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\DataStructures.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\EBEncryption.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\ExternalLibraryLoader.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\HTTP.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Chat.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\IO.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Log.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\MainSingleton.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\MD5.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Notifications.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\ObserversAndEvents.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Prefs.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\SearchProtector.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\SearchSuggestIO.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\String.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\TEAEncryption.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Timer.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Twitter.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\URL.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\Windows.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\modules\XML.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\searchplugin\conduit.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\version.txt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\ConduitAutoCompleteSearch.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCore.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko10.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko5.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko6.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko7.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko8.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko9.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\alertSettingsComponent.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\appContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\fbAlert.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\getAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\postAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\toolbarContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\defaults\unsharedAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome.manifest
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\chrome\utorrentbar.jar
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\manifest.mf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.rsa
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\META-INF\zigbert.sf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\DataStructures.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\EBEncryption.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\ExternalLibraryLoader.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\HTTP.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Chat.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\IO.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Log.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\MainSingleton.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\MD5.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Notifications.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\ObserversAndEvents.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Prefs.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\SearchProtector.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\SearchSuggestIO.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\String.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\TEAEncryption.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Timer.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Twitter.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\URL.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\Windows.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\modules\XML.jsm
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\searchplugin\conduit.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\version.txt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\ConduitAutoCompleteSearch.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\ConduitAutoCompleteSearch.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\ConduitToolbar.idl
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\ConduitToolbar.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\ConduitToolbar.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\RadioWMPCore.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\RadioWMPCore.xpt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\components\RadioWMPCoreGecko19.dll
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\alertSettingsComponent.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\appContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\engineContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\engineSettings.json
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\fbAlert.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\getAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\postAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\toolbarContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\defaults\unsharedAppsContextMenu.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\DualPackage\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\chrome.manifest
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\chrome\conduitengine.jar
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\lib\xpcom.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\META-INF\manifest.mf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\META-INF\zigbert.rsa
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\META-INF\zigbert.sf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\searchplugin\conduit.gif
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\searchplugin\conduit.ico
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\searchplugin\conduit.PNG
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\searchplugin\conduit.src
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\searchplugin\conduit.xml
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
engine@conduit.com\version.txt
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\defaults\preferences\prefs.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\chrome.manifest
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\chrome\content\ff-overlay.xul
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\chrome\content\icon.png
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\chrome\locale\en-US\overlay.properties
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
plugin2@gameplaylabs.com\setup.ini
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\datastore\cache.sqlite
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\defaults.js.bak
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\defaults\preferences\defaults.js
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\defaults\preferences\defaults.js.bak
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome.manifest
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\askToolbar.exe
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Fri-02-Mar-2012-22-33-12-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Fri-13-May-2011-11-44-07-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Fri-15-Apr-2011-23-12-55-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Mon-30-May-2011-11-45-32-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Sat-30-Jul-2011-15-29-10-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Sat-31-Mar-2012-19-42-07-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Sun-12-Feb-2012-16-45-06-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Thu-17-Nov-2011-16-34-48-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Thu-22-Mar-2012-12-40-21-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Thu-26-May-2011-16-20-02-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Thu-28-Apr-2011-12-54-45-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-03-Jan-2012-19-17-26-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-06-Sep-2011-17-13-09-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-08-Nov-2011-13-51-28-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\chrome\temp\ff-config.Tue-13-Sep-2011-18-36-54-GMT\ff-config.zip
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\icon.png
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\install.rdf
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333027918449.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333029927903.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333034498891.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333034509355.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333035667860.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333037848245.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333041690679.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333043392622.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333044139014.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333046995873.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333111647326.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333127952259.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333130114060.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333131843943.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333174068340.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333222447012.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333222524455.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333222595318.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333222925522.html
c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\extensions\
toolbar@ask.com\logs\asktb-log-1333222950975.html
c:\users\chlopi\AppData\Roaming\TrojanHunter
c:\users\chlopi\AppData\Roaming\TrojanHunter\TreeState.dat
c:\users\chlopi\Desktop\Internet Security.lnk
c:\windows\system32\asd
c:\windows\system32\asd\AccurateShutdown.exe
c:\windows\system32\asd\adkt.dll
c:\windows\system32\asd\date.cfg
c:\windows\system32\asd\doit.exe
c:\windows\system32\asd\help.chm
c:\windows\system32\asd\images\but0.gif
c:\windows\system32\asd\images\but1.gif
c:\windows\system32\asd\images\but2.gif
c:\windows\system32\asd\images\but3.gif
c:\windows\system32\asd\images\ch0.gif
c:\windows\system32\asd\images\ch1.gif
c:\windows\system32\asd\images\ch2.gif
c:\windows\system32\asd\images\ch3.gif
c:\windows\system32\asd\images\ch4.gif
c:\windows\system32\asd\images\ch5.gif
c:\windows\system32\asd\images\ch6.gif
c:\windows\system32\asd\images\ch7.gif
c:\windows\system32\asd\images\i30.gif
c:\windows\system32\asd\images\i31.gif
c:\windows\system32\asd\images\i310.gif
c:\windows\system32\asd\images\i311.gif
c:\windows\system32\asd\images\i32.gif
c:\windows\system32\asd\images\i33.gif
c:\windows\system32\asd\images\i34.gif
c:\windows\system32\asd\images\i35.gif
c:\windows\system32\asd\images\i36.gif
c:\windows\system32\asd\images\i37.gif
c:\windows\system32\asd\images\i38.gif
c:\windows\system32\asd\images\i39.gif
c:\windows\system32\asd\images\iclose0.gif
c:\windows\system32\asd\images\iclose1.gif
c:\windows\system32\asd\images\opt0.gif
c:\windows\system32\asd\images\opt1.gif
c:\windows\system32\asd\images\opt2.gif
c:\windows\system32\asd\images\opt3.gif
c:\windows\system32\asd\images\opt4.gif
c:\windows\system32\asd\images\opt5.gif
c:\windows\system32\asd\images\opt6.gif
c:\windows\system32\asd\images\opt7.gif
c:\windows\system32\asd\images\tbk.gif
c:\windows\system32\asd\images\tit.gif
c:\windows\system32\asd\images\title.gif
c:\windows\system32\asd\loadqm.exe
c:\windows\system32\asd\mylng.cfg
c:\windows\system32\asd\newsdsave.dll
c:\windows\system32\asd\rule.cfg
c:\windows\system32\asd\unins00.dat
c:\windows\system32\asd\unins00.exe
c:\windows\system32\asd\unins000.exe
c:\windows\system32\asd\w1.wav
c:\windows\system32\asd\YFSysKeys.ocx
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001Core.job
c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001UA.job
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001Core.job
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1871977560-501710343-4259429351-1001UA.job
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Files Created from 2012-03-03 to 2012-04-03 )))))))))))))))))))))))))))))))
.
.
2012-04-03 16:02 . 2012-04-03 16:06 -------- d-----w- c:\users\chlopi\AppData\Local\temp
2012-04-03 16:02 . 2012-04-03 16:02 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-29 15:50 . 2012-03-29 16:16 -------- d-----w- C:\sh4ldr
2012-03-29 15:50 . 2012-03-29 15:50 -------- d-----w- c:\program files\Enigma Software Group
2012-03-29 15:50 . 2012-03-29 16:16 -------- d-----w- c:\windows\4E0C6314A8B84026AC15084E8B63AFB5.TMP
2012-03-25 20:03 . 2012-03-25 20:03 -------- d-----w- c:\users\chlopi\AppData\Roaming\Malwarebytes
2012-03-25 20:03 . 2012-03-25 20:03 -------- d-----w- c:\programdata\Malwarebytes
2012-03-25 20:03 . 2012-03-25 20:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-25 19:28 . 2012-03-25 19:28 -------- d-----w- c:\program files\ERUNT
2012-03-24 21:31 . 2012-03-24 21:46 -------- d-----w- c:\program files\PC Drummer Trial Edition
2012-03-20 16:05 . 2012-03-20 16:05 -------- d-----w- c:\program files\ASIO4ALL v2
2012-03-20 16:05 . 2012-03-20 16:05 -------- d-----w- c:\program files\VstPlugins
2012-03-20 16:05 . 2002-07-07 22:14 1294336 ----a-w- c:\windows\system32\vorbis.acm
2012-03-20 16:05 . 2012-03-20 16:05 -------- d-----w- c:\program files\Outsim
2012-03-20 16:04 . 2012-03-20 16:05 -------- d-----w- c:\program files\Image-Line
2012-03-08 16:01 . 2012-03-08 16:01 687653 ----a-w- c:\windows\Counter-Strike 1.6 Standalone Uninstaller.exe
2012-03-08 16:00 . 2012-03-29 17:21 -------- d-----w- c:\program files\Counter-Strike 1.6 Standalone
2012-03-08 16:00 . 2012-03-08 16:00 -------- d-----w- c:\program files\Common Files\Thraex Software
2012-03-06 20:21 . 2012-03-06 20:21 -------- d-----w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-11 12:25 . 2010-12-01 14:26 140496 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-02-11 12:25 . 2010-12-01 14:26 280736 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-02-11 12:25 . 2010-10-05 18:03 280736 ----a-w- c:\windows\system32\PnkBstrB.xtr
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-31_12.43.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-21 16:13 . 2012-04-03 11:50 52144 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2012-04-03 16:07 46184 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-09-21 15:33 . 2012-04-03 16:07 14840 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1871977560-501710343-4259429351-1001_UserData.bin
- 2010-09-22 00:23 . 2012-03-31 12:44 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-22 00:23 . 2012-04-01 07:57 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-22 00:23 . 2012-04-01 07:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-09-22 00:23 . 2012-03-31 12:44 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2012-04-01 07:57 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2012-03-31 12:44 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-21 15:41 . 2012-04-03 16:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-21 15:41 . 2012-03-31 12:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-03-25 17:43 . 2012-04-03 16:06 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2012-03-25 17:43 . 2012-03-31 12:42 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2012-03-25 17:43 . 2012-04-03 16:06 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
- 2012-03-25 17:43 . 2012-03-31 12:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\History\History.IE5\index.dat
- 2012-03-25 17:43 . 2012-03-31 12:42 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
+ 2012-03-25 17:43 . 2012-04-03 16:06 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cookies\index.dat
+ 2010-09-21 15:41 . 2012-04-03 16:06 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-09-21 15:41 . 2012-03-31 12:42 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-09-21 15:41 . 2012-03-31 12:40 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-21 15:41 . 2012-04-03 16:05 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-21 15:41 . 2012-03-31 12:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-09-21 15:41 . 2012-04-03 16:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-09-21 15:41 . 2012-03-31 12:42 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-09-21 15:41 . 2012-04-03 16:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-03-31 05:36 . 2012-03-31 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-03 11:48 . 2012-04-03 16:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-04-03 11:48 . 2012-04-03 16:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-03-31 05:36 . 2012-03-31 12:40 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2012-04-03 13:55 618714 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2012-03-31 11:32 618714 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2012-04-03 13:55 107034 c:\windows\System32\perfc009.dat
- 2009-07-14 02:05 . 2012-03-31 11:32 107034 c:\windows\System32\perfc009.dat
+ 2011-07-06 18:18 . 2012-04-03 13:51 262144 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2011-07-06 18:18 . 2012-03-30 15:46 262144 c:\windows\System32\%APPDATA%\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:47 . 2012-03-30 23:05 483560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 04:47 . 2012-04-02 20:14 483560 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 02:03 . 2012-03-31 11:39 7077888 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:03 . 2012-04-03 13:42 7077888 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2012-01-13 13:15 . 2012-01-13 13:15 3745280 c:\windows\Installer\1087f6.msi
+ 2012-01-13 13:15 . 2012-04-01 09:00 3745280 c:\windows\Installer\1087f6.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-10-16 2363392]
"EADM"="c:\program files\Origin\Origin.exe" [2011-09-23 27763336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\program files\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-07-07 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-09-08 343168]
.
c:\users\chlopi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984D045-52CF-49cd-DB77-08F378FEA4DB}"= "c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll" [2010-03-24 511344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-03-04 12:31 311296 ----a-w- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BATINDICATOR]
2009-05-08 23:39 2068992 ----a-w- c:\program files\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP KEYBOARDx]
2010-02-11 17:07 710656 ----a-w- c:\program files\Hewlett-Packard\HP Desktop Keyboard\HPKEYBOARDx.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchHPOSIAPP]
2009-04-04 01:24 385024 ----a-w- c:\program files\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
2009-10-14 22:53 563736 ----a-w- c:\program files\PDF Complete\pdfsty.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-31 652360]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-15 158856]
R3 BopItU2U;BopIt Serial port driver;c:\windows\system32\DRIVERS\BopItU2U.sys [x]
R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x32.sys [x]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 OxPPort;OxPPort;c:\windows\system32\DRIVERS\OxPPort.sys [2008-07-31 82048]
R3 OxSer;OxSer;c:\windows\system32\DRIVERS\OxSer.sys [2009-09-16 83888]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-07-26 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-03-20 436792]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-07-29 115008]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-09-08 176128]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-07-29 136632]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-08-12 810144]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-07-29 96920]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-10-14 635416]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-09-08 8606208]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-09-08 248832]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-06-06 211984]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-03-04 277536]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-10-16 10:49 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/
mStart Page = hxxp://
www.bing.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\chlopi\AppData\Roaming\Mozilla\Firefox\Profiles\sg9zka62.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: di.slik.es - the Facebook Dislike Button: dislikes@dige - %profile%\extensions\dislikes@dige
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-886vo8wswek2 - c:\users\chlopi\AppData\Roaming\Antivirus Protection\securityhelper.exe
HKCU-Run-Antivirus Protection 2012 SM - c:\users\chlopi\AppData\Roaming\Antivirus Protection\securitymanager.exe
HKCU-Run-Antivirus Protection 2012 SH - c:\users\chlopi\AppData\Roaming\Antivirus Protection\securityhelper.exe
HKCU-Run-Internet Security - c:\users\chlopi\AppData\Roaming\isecurity.exe
HKLM-Run-ats - c:\windows\system32\asd\loadqm.exe
AddRemove-Accurate Shutdown_is1 - c:\windows\system32\asd\unins000.exe
AddRemove-uTorrentBar Toolbar - c:\progra~1\uTorrentBar\UNWISE.EXE
AddRemove-Antivirus Protection - c:\users\chlopi\AppData\Roaming\Antivirus Protection\securityhelper.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(5228)
c:\windows\system32\actxprxy.dll
c:\program files\Stardock\ObjectDockPlus2\ODMenu.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conhost.exe
c:\windows\system32\WUDFHost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2012-04-03 18:24:12 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-03 16:24
ComboFix2.txt 2012-03-31 13:03
.
Pre-Run: 20 808 962 048 bytes free
Post-Run: 21 462 446 080 bytes free
.
- - End Of File - - 5B8CDECE1F5ACED3A5B8696CEF12E882