Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Modrá obrazovka

V tomto fóru se řeší problematika modré smrti - BSOD

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Modrá obrazovka

#1 Příspěvek od ver3 »

Dobrý den,
chtěla bych poprosit o radu. Již podruhé se mi zobrazila modrá obrazovka, poprvé se to stalo minulý týden. Mám netbook Asus Eee 1001HA, WinXP.
Přikládám foto.
IMAG0060as.jpg
IMAG0060as.jpg (60.39 KiB) Zobrazeno 2460 x
Můžete mi poradit, co mám dělat?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#2 Příspěvek od Rudy »

Zdravím!
Otevřte adresář windows\minidump, jeho obsah zabalte do raru a přiložte k vašemu příštímu postu. Zároveň váš příspěvek přesouvám do správné sekce.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#3 Příspěvek od ver3 »

Děkuji.
Přikládám rar.
Minidump.rar
(91.71 KiB) Staženo 109 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#4 Příspěvek od Rudy »

Problém způsobuje antivir Avira. Pokud jej máte nainstalován (nejde pouze o nějaké zbytky), přeinstalujte. Jestli jsou to zbytky, bude nutné je promazat ručně.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#5 Příspěvek od ver3 »

Aviru jsem odinstalovala. Mám nyní nainstalovat znovu, nebo se poohlédnout po jiném antiviru? Tento antivir jsem instalovala asi před měsícem, předtím jsem používala AVG a notebook se mi zdál moc pomalý.


Mohla bych ještě poprosit o kontrolu?
Děkuji

Logfile of random's system information tool 1.09 (written by random/random)
Run by Verča at 2013-03-30 15:55:12
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 19 GB (26%) free of 74 GB
Total RAM: 1015 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:56:06, on 30.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ExpressFiles\EFUpdater.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Verča\Data aplikací\SearchProtect\bin\cltmng.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\SearchProtect\bin\CltMngSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Verča\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Verča.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?ctid=CT31769 ... ADEEDBA828
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Program Files\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: express-files Toolbar - {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files\express-files\prxtbexpr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: express-files - {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files\express-files\prxtbexpr.dll
O2 - BHO: GamePlayLabsBHO - {984A9162-8891-4D19-8CFE-17648BB4E1EC} - C:\Documents and Settings\Verča\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll (file missing)
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Program Files\Internet Explorer\qipsearchbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: express-files Toolbar - {88ac3cb6-596b-4217-964c-b6757ef9602d} - C:\Program Files\express-files\prxtbexpr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SearchProtect] C:\Documents and Settings\Verča\Data aplikací\SearchProtect\bin\cltmng.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe

--
End of file - 11057 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\Express FilesUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\ROC_JAN2013_TB_rmv.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, fbp@fbpurity.com:6.1.1, engine@conduit.com:3.3.3.2, {a060276a-53be-45ec-8ebe-b94b1e803179}:3.8.1.0, toolbar@ask.com:3.14.0.100010, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.2124, {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2126, avg@toolbar:10.2.0.3, {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"
prefs.js - "keyword.URL" - "http://search.conduit.com/ResultsExt.as ... 271&UM=&q="

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
lastfm-compatibility-percentage.user.js
sprotector.js

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
answers.xml
avg-secure-search.xml
avg_igeared.xml
bing.xml
creativecommons.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{88ac3cb6-596b-4217-964c-b6757ef9602d}
{a060276a-53be-45ec-8ebe-b94b1e803179}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\
askcom.xml
conduit.xml
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-30 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88ac3cb6-596b-4217-964c-b6757ef9602d}]
express-files Toolbar - C:\Program Files\express-files\prxtbexpr.dll [2012-11-06 183112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class - C:\Documents and Settings\Verča\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Program Files\Internet Explorer\qipsearchbar.dll [2009-07-09 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-04-15 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-30 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{88ac3cb6-596b-4217-964c-b6757ef9602d} - express-files Toolbar - C:\Program Files\express-files\prxtbexpr.dll [2012-11-06 183112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-04-27 17881088]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2009-04-16 630784]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2009-03-13 98304]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2009-04-16 118784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-04-09 1512744]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-04-09 79144]
"LiveUpdate"=C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [2009-06-25 712704]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-27 585728]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SearchProtectAll"=C:\Program Files\SearchProtect\bin\cltmng.exe [2013-02-20 2674464]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-07-27 397312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"SearchProtect"=C:\Documents and Settings\Verča\Data aplikací\SearchProtect\bin\cltmng.exe [2013-03-06 2731296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe

C:\Documents and Settings\Verča\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"="C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\ExpressFiles\expressdl.exe"="C:\Program Files\ExpressFiles\expressdl.exe:*:Enabled:Express Files"
"C:\Program Files\ExpressFiles\ExpressFiles.exe"="C:\Program Files\ExpressFiles\ExpressFiles.exe:*:Enabled:Express Files"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2013-03-30 15:55:13 ----D---- C:\Program Files\trend micro
2013-03-30 15:55:12 ----D---- C:\rsit
2013-03-30 03:02:08 ----A---- C:\WINDOWS\system32\javaws.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\javaw.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\java.exe
2013-03-25 21:39:46 ----A---- C:\WINDOWS\system32\GPhotos.scr
2013-03-16 03:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2013-03-12 20:29:05 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2013-03-09 12:20:42 ----D---- C:\WINDOWS\Minidump
2013-03-09 01:46:08 ----D---- C:\WINDOWS\system32\NtmsData
2013-03-08 12:59:18 ----D---- C:\Program Files\Mozilla Firefox
2013-03-01 19:37:18 ----D---- C:\Program Files\Conduit
2013-03-01 19:36:47 ----D---- C:\Program Files\express-files
2013-03-01 19:36:06 ----D---- C:\Program Files\SearchProtect
2013-03-01 19:35:46 ----D---- C:\Documents and Settings\Verča\Data aplikací\SearchProtect
2013-03-01 19:33:09 ----D---- C:\Program Files\ExpressFiles
2013-03-01 19:33:09 ----D---- C:\Documents and Settings\Verča\Data aplikací\ExpressFiles

======List of files/folders modified in the last 1 month======

2013-03-30 15:55:16 ----D---- C:\WINDOWS\Prefetch
2013-03-30 15:55:13 ----RD---- C:\Program Files
2013-03-30 15:37:51 ----D---- C:\WINDOWS\Temp
2013-03-30 15:36:33 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-03-30 15:35:26 ----D---- C:\WINDOWS\system32\drivers
2013-03-30 15:34:52 ----D---- C:\WINDOWS\system32\CatRoot2
2013-03-30 12:56:39 ----D---- C:\WINDOWS\system32
2013-03-30 12:23:21 ----D---- C:\WINDOWS\SHELLNEW
2013-03-30 12:23:19 ----D---- C:\WINDOWS\I386
2013-03-30 10:11:52 ----D---- C:\WINDOWS\Registration
2013-03-30 03:02:40 ----SHD---- C:\WINDOWS\Installer
2013-03-30 03:02:40 ----HD---- C:\Config.Msi
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-03-30 03:01:19 ----D---- C:\Program Files\Java
2013-03-30 01:33:22 ----HD---- C:\WINDOWS\inf
2013-03-30 00:45:32 ----D---- C:\WINDOWS
2013-03-29 20:45:04 ----D---- C:\Documents and Settings\Verča\Data aplikací\AIMP
2013-03-25 12:25:47 ----SHD---- C:\System Volume Information
2013-03-16 03:02:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-03-16 03:01:26 ----HD---- C:\WINDOWS\$hf_mig$
2013-03-14 03:02:31 ----A---- C:\WINDOWS\system32\MRT.exe
2013-03-14 03:02:23 ----A---- C:\WINDOWS\imsins.BAK
2013-03-14 03:01:53 ----D---- C:\Program Files\Internet Explorer
2013-03-14 03:01:34 ----D---- C:\WINDOWS\ie8updates
2013-03-12 20:29:12 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-03-09 11:01:43 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Temp
2013-03-09 10:59:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2013-03-09 10:58:00 ----D---- C:\Program Files\Common Files
2013-03-09 10:57:24 ----D---- C:\WINDOWS\system32\drivers\AVG
2013-03-09 10:50:34 ----D---- C:\Program Files\DsNET Corp
2013-03-09 10:49:22 ----D---- C:\Program Files\Ask.com
2013-03-09 10:49:12 ----SD---- C:\WINDOWS\Tasks
2013-03-09 01:46:06 ----D---- C:\WINDOWS\repair
2013-03-09 00:52:34 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-08 22:31:31 ----D---- C:\Documents and Settings\Verča\Data aplikací\BSplayer
2013-03-01 03:27:55 ----A---- C:\WINDOWS\system32\mshtml.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2008-09-12 327192]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-01 691696]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-04-27 5074944]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-03-02 38912]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2009-07-10 1015424]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-09-10 27632]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-13 1759616]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2009-04-09 208816]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-29 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-29 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-29 21568]
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-09 24576]
S3 htcnprot;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
S3 mbr;mbr; \??\C:\DOCUME~1\VERA~1\LOCALS~1\Temp\mbr.sys []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-05-16 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2011-05-25 32768]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 uvclf;uvclf; C:\WINDOWS\system32\DRIVERS\uvclf.sys [2008-11-19 39040]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CltMngSvc;Search Protect by Conduit Updater; C:\Program Files\SearchProtect\bin\CltMngSvc.exe [2013-02-20 93984]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-03-30 170912]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 253656]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-08 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#6 Příspěvek od Rudy »

Zbytky po AVG tam nejsou, jen je tam spousta zbytečností. Zkusíme to vyčistit. Aviru nainstalujte až po vyčištění. Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://stahnu.cz/tag/adw-cleaner-free-download
Uložte na plochu
Ukončete všechny programy
Klikněte na Search
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#7 Příspěvek od ver3 »

# AdwCleaner v2.109 - Logfile created 03/30/2013 at 20:30:02
# Updated 26/01/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Verča - N-J4XZQQOODOZG5
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Verča\Plocha\adwcleaner_2.110.exe
# Option [Search]


***** [Services] *****

Found : CltMngSvc

***** [Files / Folders] *****

File Found : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\Uninstall.exe
File Found : C:\Documents and Settings\Verča\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
File Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\Askcom.xml
File Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\Conduit.xml
File Found : C:\END
File Found : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Found : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\AskSearch
Folder Found : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\avg@toolbar
Folder Found : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\CT3176921
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\Conduit
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\ConduitCommon
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\CT2549263
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\CT3176921
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\{88ac3cb6-596b-4217-964c-b6757ef9602d}
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\{a060276a-53be-45ec-8ebe-b94b1e803179}
Folder Found : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\Smartbar
Folder Found : C:\Documents and Settings\Verča\Data aplikací\OpenCandy
Folder Found : C:\Documents and Settings\Verča\Data aplikací\SearchProtect
Folder Found : C:\Documents and Settings\Verča\Local Settings\Data aplikací\Conduit
Folder Found : C:\Documents and Settings\Verča\Local Settings\Data aplikací\express-files
Folder Found : C:\Documents and Settings\Verča\Local Settings\Data aplikací\OpenCandy
Folder Found : C:\Program Files\Ask.com
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\express-files
Folder Found : C:\Program Files\SearchProtect

***** [Registry] *****

Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\ConduitSearchScopes
Key Found : HKCU\Software\express-files
Key Found : HKCU\Software\GamePlayLabs
Key Found : HKCU\Software\IGearSettings
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\SearchProtect
Key Found : HKCU\Software\SmartBar
Key Found : HKCU\Toolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{65C994A2-C65A-4A20-BA92-AADAFC0DCE49}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{7AD1455F-5ACB-4A56-80AD-A1EDD5A2174B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2549263
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3176921
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\express-files
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\ocphobfcfafpclibolpjdafgaffkaoci
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5895770C-4E0C-4F2F-B86E-555AC905BE77}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70DD7392-427E-40A1-B7C8-617E1999FE21}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\express-files Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AD1455F-5ACB-4A56-80AD-A1EDD5A2174B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\express-files Toolbar
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : HKLM\Software\SearchProtect
Key Found : HKU\S-1-5-21-3283330612-449700776-2936646239-1005\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKU\S-1-5-21-3283330612-449700776-2936646239-1005\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Found : HKU\S-1-5-21-3283330612-449700776-2936646239-1005\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com/?ctid=CT3176921&octid=CT3176921&SearchSource=61&CUI=UN22716042071426860&UM=UM_ID&UP=SPE359897C-8E05-43F5-A494-7AADEEDBA828
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.qip.ru
[HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.qip.ru/ie
[HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://search.qip.ru/ie

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\prefs.js

Found : user_pref("CT2549263..clientLogIsEnabled", false);
Found : user_pref("CT2549263..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2549263..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2549263.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2549263.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2549263.AppTrackingLastCheckTime", "Thu Jul 07 2011 21:18:35 GMT+0200");
Found : user_pref("CT2549263.BrowserCompStateIsOpen_129681782619538716", true);
Found : user_pref("CT2549263.BrowserCompStateIsOpen_129738909652389324", true);
Found : user_pref("CT2549263.BrowserCompStateIsOpen_130082408922954284", true);
Found : user_pref("CT2549263.BrowserCompStateIsOpen_1359634298000", true);
Found : user_pref("CT2549263.CTID", "CT2549263");
Found : user_pref("CT2549263.Chat.Meebo.ServerLastCheckTime", "");
Found : user_pref("CT2549263.Chat.Meebo.ServerLastResponseTime", "Wed Apr 18 2012 23:19:01 GMT+0200");
Found : user_pref("CT2549263.Chat.Meebo.rooms.2030dff2c5edb1", 9);
Found : user_pref("CT2549263.Chat.Meebo.rooms.30plusa87dca4f", 19);
Found : user_pref("CT2549263.Chat.Meebo.rooms.communitychatc26d8828", 0);
Found : user_pref("CT2549263.Chat.Meebo.rooms.entertainmentc0ed09fb", 1);
Found : user_pref("CT2549263.Chat.Meebo.rooms.health3693b665", 0);
Found : user_pref("CT2549263.Chat.Meebo.rooms.musicj375cf270", 6);
Found : user_pref("CT2549263.Chat.Meebo.rooms.newsxu117b840d", 16);
Found : user_pref("CT2549263.Chat.Meebo.rooms.recreationab17d1f9", 0);
Found : user_pref("CT2549263.Chat.Meebo.rooms.spirituality39155c53", 5);
Found : user_pref("CT2549263.Chat.Meebo.rooms.sports522528d3", 7);
Found : user_pref("CT2549263.Chat.Meebo.rooms.technology8bb9fd5b", 1);
Found : user_pref("CT2549263.Chat.Meebo.rooms.teenagers833b8249", 2);
Found : user_pref("CT2549263.Chat.Meebo.rooms.travel8c2e48db", 0);
Found : user_pref("CT2549263.Chat.Meebo.rooms.videogames2fe066e0", 0);
Found : user_pref("CT2549263.Chat.ServerLastCheckTime", "Wed Apr 18 2012 23:18:56 GMT+0200");
Found : user_pref("CT2549263.CurrentServerDate", "30-3-2013");
Found : user_pref("CT2549263.DialogsAlignMode", "LTR");
Found : user_pref("CT2549263.DialogsGetterLastCheckTime", "Thu Mar 28 2013 16:47:08 GMT+0100");
Found : user_pref("CT2549263.DownloadReferralCookieData", "");
Found : user_pref("CT2549263.EMailNotifierPollDate", "Thu Jul 07 2011 21:33:23 GMT+0200");
Found : user_pref("CT2549263.FeedLastCount129118271027024187", 30);
Found : user_pref("CT2549263.FeedPollDate128795077986382124", "Thu Jul 07 2011 21:18:22 GMT+0200");
Found : user_pref("CT2549263.FeedPollDate128795078397943899", "Thu Jul 07 2011 21:18:22 GMT+0200");
Found : user_pref("CT2549263.FeedTTL128795078397943899", 40);
Found : user_pref("CT2549263.FirstServerDate", "7-7-2011");
Found : user_pref("CT2549263.FirstTime", true);
Found : user_pref("CT2549263.FirstTimeFF3", true);
Found : user_pref("CT2549263.FixPageNotFoundErrors", true);
Found : user_pref("CT2549263.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2549263.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2549263.HasUserGlobalKeys", true);
Found : user_pref("CT2549263.Initialize", true);
Found : user_pref("CT2549263.InitializeCommonPrefs", true);
Found : user_pref("CT2549263.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2549263.InstallationType", "UnknownIntegration");
Found : user_pref("CT2549263.InstalledDate", "Wed Jul 06 2011 23:07:49 GMT+0200");
Found : user_pref("CT2549263.InvalidateCache", false);
Found : user_pref("CT2549263.IsGrouping", false);
Found : user_pref("CT2549263.IsMulticommunity", false);
Found : user_pref("CT2549263.IsOpenThankYouPage", false);
Found : user_pref("CT2549263.IsOpenUninstallPage", true);
Found : user_pref("CT2549263.LanguagePackLastCheckTime", "Sat Mar 30 2013 18:06:05 GMT+0100");
Found : user_pref("CT2549263.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2549263.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2549263.LastLogin_3.12.0.7", "Wed Apr 25 2012 20:57:02 GMT+0200");
Found : user_pref("CT2549263.LastLogin_3.12.2.3", "Tue May 29 2012 22:00:02 GMT+0200");
Found : user_pref("CT2549263.LastLogin_3.13.0.6", "Sat Jul 14 2012 22:38:29 GMT+0200");
Found : user_pref("CT2549263.LastLogin_3.14.1.0", "Wed Aug 22 2012 10:29:25 GMT+0200");
Found : user_pref("CT2549263.LastLogin_3.15.1.0", "Wed Nov 07 2012 12:39:54 GMT+0100");
Found : user_pref("CT2549263.LastLogin_3.16.0.3", "Sun Feb 10 2013 18:13:57 GMT+0100");
Found : user_pref("CT2549263.LastLogin_3.18.0.7", "Sat Mar 30 2013 19:36:01 GMT+0100");
Found : user_pref("CT2549263.LastLogin_3.3.3.2", "Thu Jul 07 2011 21:18:21 GMT+0200");
Found : user_pref("CT2549263.LatestVersion", "3.18.0.7");
Found : user_pref("CT2549263.Locale", "en-us");
Found : user_pref("CT2549263.MCDetectTooltipHeight", "83");
Found : user_pref("CT2549263.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2549263.MCDetectTooltipWidth", "295");
Found : user_pref("CT2549263.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2549263.RadioIsPodcast", false);
Found : user_pref("CT2549263.RadioLastCheckTime", "Thu Jul 07 2011 23:08:17 GMT+0200");
Found : user_pref("CT2549263.RadioLastUpdateIPServer", "3");
Found : user_pref("CT2549263.RadioLastUpdateServer", "129118362079830000");
Found : user_pref("CT2549263.RadioMediaID", "20117398");
Found : user_pref("CT2549263.RadioMediaType", "Media Player");
Found : user_pref("CT2549263.RadioMenuSelectedID", "EBRadioMenu_CT254926320117398");
Found : user_pref("CT2549263.RadioStationName", "Radio%20Hip-Hop%2FRap(USA)");
Found : user_pref("CT2549263.RadioStationURL", "hxxp://206.51.233.231/007HipHop");
Found : user_pref("CT2549263.SavedHomepage", "hxxp://www.seznam.cz/");
Found : user_pref("CT2549263.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2549263.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254[...]
Found : user_pref("CT2549263.SearchInNewTabEnabled", true);
Found : user_pref("CT2549263.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2549263.SearchInNewTabLastCheckTime", "Sat Mar 30 2013 16:13:57 GMT+0100");
Found : user_pref("CT2549263.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2549263.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Found : user_pref("CT2549263.ServiceMapLastCheckTime", "Sat Mar 30 2013 18:05:54 GMT+0100");
Found : user_pref("CT2549263.SettingsLastCheckTime", "Sat Mar 30 2013 15:35:57 GMT+0100");
Found : user_pref("CT2549263.SettingsLastUpdate", "1364649130");
Found : user_pref("CT2549263.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2549263.ThirdPartyComponentsLastCheck", "Wed Jul 06 2011 23:07:29 GMT+0200");
Found : user_pref("CT2549263.ThirdPartyComponentsLastUpdate", "1246786978");
Found : user_pref("CT2549263.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2549263.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2549263");
Found : user_pref("CT2549263.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2549263.UserID", "UN93446014690826653");
Found : user_pref("CT2549263.ValidationData_Search", 0);
Found : user_pref("CT2549263.ValidationData_Toolbar", 2);
Found : user_pref("CT2549263.alertChannelId", "942243");
Found : user_pref("CT2549263.backendstorage./9b+7e+x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e,x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e-x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e.x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e/x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e06cg5el8:", "6E6D6C726F6B6E6F7578");
Found : user_pref("CT2549263.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737278757174757B7E242F4B4947[...]
Found : user_pref("CT2549263.backendstorage./9b+7e0x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e1x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e2x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e3x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e4x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e5x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e6x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e7x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e8x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e9x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e:x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e;x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e<x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e=x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e>x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e?x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7e@x305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7eax305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Found : user_pref("CT2549263.backendstorage./9b+7ebx305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7ecx305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7edx305", "2423");
Found : user_pref("CT2549263.backendstorage./9b+7etx305", "2423");
Found : user_pref("CT2549263.backendstorage./9b-0?3g>d", "6E3A3D3D3D41756D7A46787A47204C4A7D7E2522507C232A22[...]
Found : user_pref("CT2549263.backendstorage./9b-0?3g@6:5;", "");
Found : user_pref("CT2549263.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Found : user_pref("CT2549263.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
Found : user_pref("CT2549263.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Found : user_pref("CT2549263.backendstorage./9b5ba==9cjag", "6D3B3F3F6D6B6C437A6F457445474B777D7E7E794D");
Found : user_pref("CT2549263.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6C706F6C6E707673727372");
Found : user_pref("CT2549263.backendstorage./9b9643g3/9e", "6A");
Found : user_pref("CT2549263.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
Found : user_pref("CT2549263.backendstorage./9b<:222h64<", "393F352F3E");
Found : user_pref("CT2549263.backendstorage./9b<:222h64<l8daj", "6D7070707673757976712A7973727C79757E22");
Found : user_pref("CT2549263.backendstorage./9b=+03eh8h8j?:", "4443");
Found : user_pref("CT2549263.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Found : user_pref("CT2549263.backendstorage./9b?b0d:8aj62<h", "6D");
Found : user_pref("CT2549263.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Found : user_pref("CT2549263.backendstorage.cb_experience_000", "3239");
Found : user_pref("CT2549263.backendstorage.cb_user_id_000", "4342363130323234353638375F46697265666F78");
Found : user_pref("CT2549263.backendstorage.cbcountry_001", "435A");
Found : user_pref("CT2549263.backendstorage.cbfirsttime", "576564204F637420313020323031322031303A31313A30342[...]
Found : user_pref("CT2549263.backendstorage.gk_hsselite_notif_sent", "73656E74");
Found : user_pref("CT2549263.backendstorage.installationdate0.2690270998198123", "31333439313539383833343933[...]
Found : user_pref("CT2549263.backendstorage.printitgreenstatus", "74727565");
Found : user_pref("CT2549263.backendstorage.toolbarappheartbeat", "7B22223A313334393135393838333337387D");
Found : user_pref("CT2549263.backendstorage.toolbarnotificationqueue", "5B7B22617070223A302E3236393032373039[...]
Found : user_pref("CT2549263.backendstorage.toolbarnotificationsettings", "7B2273656E644E6F74696669636174696[...]
Found : user_pref("CT2549263.backendstorage.toolbarnotificationuserid", "3639373436363531343732");
Found : user_pref("CT2549263.backendstorage.url_history0001", "687474703A2F2F7777772E676F6F676C652E637A2F757[...]
Found : user_pref("CT2549263.components.1000080", true);
Found : user_pref("CT2549263.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2549263.globalFirstTimeInfoLastCheckTime", "Thu Jul 07 2011 21:18:21 GMT+0200");
Found : user_pref("CT2549263.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2549263.initDone", true);
Found : user_pref("CT2549263.isAppTrackingManagerOn", true);
Found : user_pref("CT2549263.myStuffEnabled", true);
Found : user_pref("CT2549263.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2549263.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2549263.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2549263.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2549263.oldAppsList", "129118270998274454,129118270998586956,129167878631062901,1291182[...]
Found : user_pref("CT2549263.revertSettingsEnabled", true);
Found : user_pref("CT2549263.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2549263.searchProtectorEnableByLogin", true);
Found : user_pref("CT2549263.testingCtid", "");
Found : user_pref("CT2549263.toolbarAppMetaDataLastCheckTime", "Sat Mar 30 2013 16:14:00 GMT+0100");
Found : user_pref("CT2549263.toolbarContextMenuLastCheckTime", "Wed Jul 06 2011 23:07:52 GMT+0200");
Found : user_pref("CT2549263.usagesFlag", 2);
Found : user_pref("CT3176921.1000082.isPlayDisplay", "true");
Found : user_pref("CT3176921.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description[...]
Found : user_pref("CT3176921.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3176921.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Found : user_pref("CT3176921.FF19Solved", "true");
Found : user_pref("CT3176921.FirstTime", "true");
Found : user_pref("CT3176921.FirstTimeFF3", "true");
Found : user_pref("CT3176921.PG_ENABLE", "dHJ1ZQ==");
Found : user_pref("CT3176921.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT317[...]
Found : user_pref("CT3176921.TopHitsConfig.enc", "ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC[...]
Found : user_pref("CT3176921.UserID", "UN62743415169533271");
Found : user_pref("CT3176921.addressBarTakeOverEnabledInHidden", "true");
Found : user_pref("CT3176921.autoDisableScopes", -1);
Found : user_pref("CT3176921.browser.search.defaultthis.engineName", "true");
Found : user_pref("CT3176921.defaultSearch", "true");
Found : user_pref("CT3176921.enableAlerts", "always");
Found : user_pref("CT3176921.enableFix404ByUser", "FALSE");
Found : user_pref("CT3176921.enableSearchFromAddressBar", "true");
Found : user_pref("CT3176921.firstTimeDialogOpened", "true");
Found : user_pref("CT3176921.fixPageNotFoundError", "true");
Found : user_pref("CT3176921.fixPageNotFoundErrorByUser", "true");
Found : user_pref("CT3176921.fixPageNotFoundErrorInHidden", "true");
Found : user_pref("CT3176921.fixUrls", true);
Found : user_pref("CT3176921.harvest_last_targeted_visit_absolutelyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_azlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_bollywoodlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_cowboylyrics.org.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_darklyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_elyrics.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_hindilyrix.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_hitslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_leoslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_letssingit.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyred.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricinterpretations.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyrics-p.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsdepot.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsfind.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsfreak.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsmania.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsmode.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsocean.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsondemand.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsoverload.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_lyricsplanet.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_metrolyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_mp3lyrics.org.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_nomorelyrics.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_oldielyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_onlylyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_plyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_rapgenius.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_songlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_songmeanings.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_stlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_sweetslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_thelyricarchive.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_uplyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_last_targeted_visit_urbanlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_absolutelyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_azlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_bollywoodlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_cowboylyrics.org.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_darklyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_elyrics.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_hindilyrix.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_hitslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_leoslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_letssingit.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyred.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricinterpretations.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyrics-p.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsdepot.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsfind.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsfreak.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsmania.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsmode.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsocean.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsondemand.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsoverload.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_lyricsplanet.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_metrolyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_mp3lyrics.org.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_nomorelyrics.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_oldielyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_onlylyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_plyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_rapgenius.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_songlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_songmeanings.net.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_stlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_sweetslyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_thelyricarchive.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_uplyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_post_urls_urbanlyrics.com.enc", "bnVsbA==");
Found : user_pref("CT3176921.harvest_recent.enc", "W1siaHR0cDovL3d3dy5nb29nbGUuY3ovdXJsP3NhPXQmcmN0PWomcT0mZ[...]
Found : user_pref("CT3176921.homepageuserchanged", true);
Found : user_pref("CT3176921.installDate", "1/3/2013 19:35:38");
Found : user_pref("CT3176921.installId", "stub.exe");
Found : user_pref("CT3176921.installType", "conduitnsisintegration");
Found : user_pref("CT3176921.isCheckedStartAsHidden", true);
Found : user_pref("CT3176921.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3176921.isFirstTimeToolbarLoading", "false");
Found : user_pref("CT3176921.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3176921.keyword", "true");
Found : user_pref("CT3176921.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[...]
Found : user_pref("CT3176921.lastVersion", "10.15.0.562");
Found : user_pref("CT3176921.mam_gk_AdOptimizer_appState.enc", "b24=");
Found : user_pref("CT3176921.mam_gk_Coming_Up_Next_appState.enc", "b24=");
Found : user_pref("CT3176921.mam_gk_CouponBuddy_appState.enc", "b24=");
Found : user_pref("CT3176921.mam_gk_PriceGong_appState.enc", "b24=");
Found : user_pref("CT3176921.mam_gk_appStateReportTime.enc", "MTM2MjE3NzQ4Nzg0Ng==");
Found : user_pref("CT3176921.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9w[...]
Found : user_pref("CT3176921.mam_gk_appsDefaultEnabled.enc", "dHJ1ZQ==");
Found : user_pref("CT3176921.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkNvdXBvbkJ1ZGR5Iiw[...]
Found : user_pref("CT3176921.mam_gk_currentVersion.enc", "MS40LjMuMQ==");
Found : user_pref("CT3176921.mam_gk_first_time.enc", "MQ==");
Found : user_pref("CT3176921.mam_gk_installer_preapproved.enc", "dHJ1ZQ==");
Found : user_pref("CT3176921.mam_gk_lastLoginTime.enc", "MTM2MjE3NzQ4MzY5OQ==");
Found : user_pref("CT3176921.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[...]
Found : user_pref("CT3176921.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
Found : user_pref("CT3176921.mam_gk_settings1.4.3.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[...]
Found : user_pref("CT3176921.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
Found : user_pref("CT3176921.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Found : user_pref("CT3176921.mam_gk_userId.enc", "OTRhOTI5YTQtY2RiNy00NTgyLWFmMmQtYjBjNzliZTE0OThl");
Found : user_pref("CT3176921.mam_gk_user_apps_selection.enc", "");
Found : user_pref("CT3176921.migrateAppsAndComponents", true);
Found : user_pref("CT3176921.myThings_app_locale.enc", "Q1o=");
Found : user_pref("CT3176921.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fstahnu.cz%2Ftag%[...]
Found : user_pref("CT3176921.openThankYouPage", "false");
Found : user_pref("CT3176921.openUninstallPage", "true");
Found : user_pref("CT3176921.revertSettingsEnabled", "false");
Found : user_pref("CT3176921.sac-periodic-reports.enc", "eyJ5dHRfcGluZ18wIjpbMTM2MjE3Mjk1ODI2NCwxNDQwMDAwMF1[...]
Found : user_pref("CT3176921.sac-user-ab-groups.enc", "eyJmZWVkIjo4OCwiaG92ZXJfZWZmZWN0Ijo2NSwiY2FsbF90b19hY[...]
Found : user_pref("CT3176921.sac-user-id.enc", "ImVhYzhhZDc1LTBkZTctNDE3Zi1hYjA3LWU4MmUwYzBmMzlhMiI=");
Found : user_pref("CT3176921.sac-yt-first-ping.enc", "MTM2MjE3Mjk1ODE5Mg==");
Found : user_pref("CT3176921.search.searchAppId", "10000002");
Found : user_pref("CT3176921.search.searchCount", "0");
Found : user_pref("CT3176921.searchFromAddressBarEnabledByUser", "true");
Found : user_pref("CT3176921.searchInNewTabEnabledByUser", "true");
Found : user_pref("CT3176921.searchInNewTabEnabledInHidden", "true");
Found : user_pref("CT3176921.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3176921.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3176921.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3176921.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1362163071788");
Found : user_pref("CT3176921.serviceLayer_services_appsMetadata_lastUpdate", "1362163070863");
Found : user_pref("CT3176921.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1362163070926");
Found : user_pref("CT3176921.serviceLayer_services_location_lastUpdate", "1364591993181");
Found : user_pref("CT3176921.serviceLayer_services_login_10.14.65.43_lastUpdate", "1364118204512");
Found : user_pref("CT3176921.serviceLayer_services_login_10.15.0.562_lastUpdate", "1364668879918");
Found : user_pref("CT3176921.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1362163071315");
Found : user_pref("CT3176921.serviceLayer_services_searchAPI_lastUpdate", "1362163068039");
Found : user_pref("CT3176921.serviceLayer_services_serviceMap_lastUpdate", "1364591992662");
Found : user_pref("CT3176921.serviceLayer_services_setupAPI_lastUpdate", "1362163068874");
Found : user_pref("CT3176921.serviceLayer_services_toolbarContextMenu_lastUpdate", "1362163070545");
Found : user_pref("CT3176921.serviceLayer_services_toolbarSettings_lastUpdate", "1364668882888");
Found : user_pref("CT3176921.serviceLayer_services_translation_lastUpdate", "1364591995045");
Found : user_pref("CT3176921.settingsINI", true);
Found : user_pref("CT3176921.shouldFirstTimeDialog", "false");
Found : user_pref("CT3176921.showToolbarPermission", "false");
Found : user_pref("CT3176921.smartbar.CTID", "CT3176921");
Found : user_pref("CT3176921.smartbar.Uninstall", "0");
Found : user_pref("CT3176921.smartbar.homepage", true);
Found : user_pref("CT3176921.smartbar.isHidden", true);
Found : user_pref("CT3176921.smartbar.toolbarName", "express-files ");
Found : user_pref("CT3176921.startPage", "true");
Found : user_pref("CT3176921.toolbarBornServerTime", "1-3-2013");
Found : user_pref("CT3176921.toolbarCurrentServerTime", "30-3-2013");
Found : user_pref("CT3176921.toolbarLoginClientTime", "Mon Mar 25 2013 13:10:43 GMT+0100");
Found : user_pref("CT3176921.url_history0001.enc", "aHR0cDovL2xvZ2luLnN6bi5jei8/c2VydmljZUlkPWxpZGUmbG9nZ2Vk[...]
Found : user_pref("CT3176921.ytt-mam-test-ol-ts.enc", 671925469);
Found : user_pref("CT3176921.ytt-mam-test-uid-ol.enc", "YWFmMzU1MzItMDY0MS00OWIzLWI1ZTEtYjVjZDA3ZTgxYjRk");
Found : user_pref("CT3176921_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2549263/CT2549263[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/UK", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/942243/938027/UK", "\"0\"")[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2549263", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2549263",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2549263/CT2549263[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Found : user_pref("CommunityToolbar.EngineHiddenByUser", true);
Found : user_pref("CommunityToolbar.EngineOwner", "");
Found : user_pref("CommunityToolbar.EngineOwnerGuid", "{a060276a-53be-45ec-8ebe-b94b1e803179}");
Found : user_pref("CommunityToolbar.EngineOwnerToolbarId", "expat_shield");
Found : user_pref("CommunityToolbar.IsEngineShown", false);
Found : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Found : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2549263");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{a060276a-53be-45ec-8ebe-b94b1e803179}");
Found : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "expat_shield");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.avg.com/route/?d=4b4a3a57&[...]
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2549263");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2549263");
Found : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Feb 13 2012 01:56:23 GMT+01[...]
Found : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Apr 18 2012 11:44:40 GMT+0200");
Found : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.alert.locale", "en");
Found : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Apr 18 2012 11:44:29 GMT+0200");
Found : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Found : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.alert.userId", "761e5e9e-5484-4fa0-a775-cf472bc45c28");
Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Jul 07 2011 23:07:53 GMT+0200");
Found : user_pref("CommunityToolbar.globalUserId", "b211da13-d7d8-4c0c-b950-def3040f6169");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2549263");
Found : user_pref("CommunityToolbar.killedEngine", true);
Found : user_pref("CommunityToolbar.undefined", "");
Found : user_pref("Smartbar.ConduitHomepagesList", "");
Found : user_pref("Smartbar.ConduitSearchEngineList", "express-files Customized Web Search");
Found : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3176921[...]
Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3176921");
Found : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Data aplikací\\AVG S[...]
Found : user_pref("avg.install.userSPSettings", "Ask.com");
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultthis.engineName", "express-files Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3176921&Sea[...]
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("browser.search.selectedEngine", "express-files Customized Web Search");
Found : user_pref("extensions.plugin2@gameplaylabs.com.fr", "1301772315");
Found : user_pref("extensions.plugin2@gameplaylabs.com.ranonce", true);
Found : user_pref("extensions.plugin2@gameplaylabs.com.rule_/", "1301772335");
Found : user_pref("extensions.plugin2@gameplaylabs.com.rule_h", "1301772335");
Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2549263&q=");
Found : user_pref("smartBar.searchInNewTabOwner", "CT3176921");
Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3176921&octid=CT3176921[...]
Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[...]
Found : user_pref("smartbar.machineId", "77UD6TD1GATI39QUYXQ6C8SKKPNAPKI40CD88WTEALONB9KBJBOB441OYQUTVHRDNWJ[...]
Found : user_pref("smartbar.originalHomepage", "hxxp://www.seznam.cz/");
Found : user_pref("smartbar.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254[...]
Found : user_pref("smartbar.originalSearchEngine", "Ask.com");

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\Verča\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [46332 octets] - [30/03/2013 20:28:19]
AdwCleaner[R2].txt - [46262 octets] - [30/03/2013 20:30:02]

########## EOF - C:\AdwCleaner[R2].txt - [46323 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#8 Příspěvek od Rudy »

Spusťte znovu ADWCleaner a klikněte na >Delete<. Vložte nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#9 Příspěvek od ver3 »

Děkuju.

# AdwCleaner v2.109 - Logfile created 03/30/2013 at 20:50:45
# Updated 26/01/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Verča - N-J4XZQQOODOZG5
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Verča\Plocha\adwcleaner_2.110.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : CltMngSvc

***** [Files / Folders] *****

File Deleted : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\Uninstall.exe
File Deleted : C:\Documents and Settings\Verča\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
File Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\Askcom.xml
File Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\Conduit.xml
File Deleted : C:\END
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Deleted : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\AskSearch
Folder Deleted : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\avg@toolbar
Folder Deleted : C:\DOCUME~1\VERA~1\LOCALS~1\Temp\CT3176921
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\Conduit
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\ConduitCommon
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\CT2549263
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\CT3176921
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\{88ac3cb6-596b-4217-964c-b6757ef9602d}
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\{a060276a-53be-45ec-8ebe-b94b1e803179}
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\Smartbar
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\OpenCandy
Folder Deleted : C:\Documents and Settings\Verča\Data aplikací\SearchProtect
Folder Deleted : C:\Documents and Settings\Verča\Local Settings\Data aplikací\Conduit
Folder Deleted : C:\Documents and Settings\Verča\Local Settings\Data aplikací\express-files
Folder Deleted : C:\Documents and Settings\Verča\Local Settings\Data aplikací\OpenCandy
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\express-files
Folder Deleted : C:\Program Files\SearchProtect

***** [Registry] *****

Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\express-files
Key Deleted : HKCU\Software\GamePlayLabs
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{65C994A2-C65A-4A20-BA92-AADAFC0DCE49}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7AD1455F-5ACB-4A56-80AD-A1EDD5A2174B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8E7AD93B-3E87-423D-947F-A321FA7E31C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2549263
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3176921
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\express-files
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ocphobfcfafpclibolpjdafgaffkaoci
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5895770C-4E0C-4F2F-B86E-555AC905BE77}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70DD7392-427E-40A1-B7C8-617E1999FE21}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\express-files Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88AC3CB6-596B-4217-964C-B6757EF9602D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AD1455F-5ACB-4A56-80AD-A1EDD5A2174B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\express-files Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\Software\SearchProtect
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{88AC3CB6-596B-4217-964C-B6757EF9602D}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com/?ctid=CT3176921&octid=CT3176921&SearchSource=61&CUI=UN22716042071426860&UM=UM_ID&UP=SPE359897C-8E05-43F5-A494-7AADEEDBA828 --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://search.qip.ru --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Page_URL] = hxxp://search.qip.ru --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Default_Search_URL] = hxxp://search.qip.ru --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://search.qip.ru/ie --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://search.qip.ru/ie --> hxxp://www.google.com

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\prefs.js

Deleted : user_pref("CT2549263..clientLogIsEnabled", false);
Deleted : user_pref("CT2549263..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2549263..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2549263.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2549263.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2549263.AppTrackingLastCheckTime", "Thu Jul 07 2011 21:18:35 GMT+0200");
Deleted : user_pref("CT2549263.BrowserCompStateIsOpen_129681782619538716", true);
Deleted : user_pref("CT2549263.BrowserCompStateIsOpen_129738909652389324", true);
Deleted : user_pref("CT2549263.BrowserCompStateIsOpen_130082408922954284", true);
Deleted : user_pref("CT2549263.BrowserCompStateIsOpen_1359634298000", true);
Deleted : user_pref("CT2549263.CTID", "CT2549263");
Deleted : user_pref("CT2549263.Chat.Meebo.ServerLastCheckTime", "");
Deleted : user_pref("CT2549263.Chat.Meebo.ServerLastResponseTime", "Wed Apr 18 2012 23:19:01 GMT+0200");
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.2030dff2c5edb1", 9);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.30plusa87dca4f", 19);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.communitychatc26d8828", 0);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.entertainmentc0ed09fb", 1);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.health3693b665", 0);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.musicj375cf270", 6);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.newsxu117b840d", 16);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.recreationab17d1f9", 0);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.spirituality39155c53", 5);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.sports522528d3", 7);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.technology8bb9fd5b", 1);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.teenagers833b8249", 2);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.travel8c2e48db", 0);
Deleted : user_pref("CT2549263.Chat.Meebo.rooms.videogames2fe066e0", 0);
Deleted : user_pref("CT2549263.Chat.ServerLastCheckTime", "Wed Apr 18 2012 23:18:56 GMT+0200");
Deleted : user_pref("CT2549263.CurrentServerDate", "30-3-2013");
Deleted : user_pref("CT2549263.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2549263.DialogsGetterLastCheckTime", "Thu Mar 28 2013 16:47:08 GMT+0100");
Deleted : user_pref("CT2549263.DownloadReferralCookieData", "");
Deleted : user_pref("CT2549263.EMailNotifierPollDate", "Thu Jul 07 2011 21:33:23 GMT+0200");
Deleted : user_pref("CT2549263.FeedLastCount129118271027024187", 30);
Deleted : user_pref("CT2549263.FeedPollDate128795077986382124", "Thu Jul 07 2011 21:18:22 GMT+0200");
Deleted : user_pref("CT2549263.FeedPollDate128795078397943899", "Thu Jul 07 2011 21:18:22 GMT+0200");
Deleted : user_pref("CT2549263.FeedTTL128795078397943899", 40);
Deleted : user_pref("CT2549263.FirstServerDate", "7-7-2011");
Deleted : user_pref("CT2549263.FirstTime", true);
Deleted : user_pref("CT2549263.FirstTimeFF3", true);
Deleted : user_pref("CT2549263.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2549263.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2549263.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2549263.HasUserGlobalKeys", true);
Deleted : user_pref("CT2549263.Initialize", true);
Deleted : user_pref("CT2549263.InitializeCommonPrefs", true);
Deleted : user_pref("CT2549263.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2549263.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2549263.InstalledDate", "Wed Jul 06 2011 23:07:49 GMT+0200");
Deleted : user_pref("CT2549263.InvalidateCache", false);
Deleted : user_pref("CT2549263.IsGrouping", false);
Deleted : user_pref("CT2549263.IsMulticommunity", false);
Deleted : user_pref("CT2549263.IsOpenThankYouPage", false);
Deleted : user_pref("CT2549263.IsOpenUninstallPage", true);
Deleted : user_pref("CT2549263.LanguagePackLastCheckTime", "Sat Mar 30 2013 18:06:05 GMT+0100");
Deleted : user_pref("CT2549263.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2549263.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2549263.LastLogin_3.12.0.7", "Wed Apr 25 2012 20:57:02 GMT+0200");
Deleted : user_pref("CT2549263.LastLogin_3.12.2.3", "Tue May 29 2012 22:00:02 GMT+0200");
Deleted : user_pref("CT2549263.LastLogin_3.13.0.6", "Sat Jul 14 2012 22:38:29 GMT+0200");
Deleted : user_pref("CT2549263.LastLogin_3.14.1.0", "Wed Aug 22 2012 10:29:25 GMT+0200");
Deleted : user_pref("CT2549263.LastLogin_3.15.1.0", "Wed Nov 07 2012 12:39:54 GMT+0100");
Deleted : user_pref("CT2549263.LastLogin_3.16.0.3", "Sun Feb 10 2013 18:13:57 GMT+0100");
Deleted : user_pref("CT2549263.LastLogin_3.18.0.7", "Sat Mar 30 2013 19:36:01 GMT+0100");
Deleted : user_pref("CT2549263.LastLogin_3.3.3.2", "Thu Jul 07 2011 21:18:21 GMT+0200");
Deleted : user_pref("CT2549263.LatestVersion", "3.18.0.7");
Deleted : user_pref("CT2549263.Locale", "en-us");
Deleted : user_pref("CT2549263.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2549263.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2549263.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2549263.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2549263.RadioIsPodcast", false);
Deleted : user_pref("CT2549263.RadioLastCheckTime", "Thu Jul 07 2011 23:08:17 GMT+0200");
Deleted : user_pref("CT2549263.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2549263.RadioLastUpdateServer", "129118362079830000");
Deleted : user_pref("CT2549263.RadioMediaID", "20117398");
Deleted : user_pref("CT2549263.RadioMediaType", "Media Player");
Deleted : user_pref("CT2549263.RadioMenuSelectedID", "EBRadioMenu_CT254926320117398");
Deleted : user_pref("CT2549263.RadioStationName", "Radio%20Hip-Hop%2FRap(USA)");
Deleted : user_pref("CT2549263.RadioStationURL", "hxxp://206.51.233.231/007HipHop");
Deleted : user_pref("CT2549263.SavedHomepage", "hxxp://www.seznam.cz/");
Deleted : user_pref("CT2549263.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2549263.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254[...]
Deleted : user_pref("CT2549263.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2549263.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2549263.SearchInNewTabLastCheckTime", "Sat Mar 30 2013 16:13:57 GMT+0100");
Deleted : user_pref("CT2549263.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2549263.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
Deleted : user_pref("CT2549263.ServiceMapLastCheckTime", "Sat Mar 30 2013 18:05:54 GMT+0100");
Deleted : user_pref("CT2549263.SettingsLastCheckTime", "Sat Mar 30 2013 20:30:31 GMT+0100");
Deleted : user_pref("CT2549263.SettingsLastUpdate", "1364649130");
Deleted : user_pref("CT2549263.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2549263.ThirdPartyComponentsLastCheck", "Wed Jul 06 2011 23:07:29 GMT+0200");
Deleted : user_pref("CT2549263.ThirdPartyComponentsLastUpdate", "1246786978");
Deleted : user_pref("CT2549263.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2549263.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2549263");
Deleted : user_pref("CT2549263.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2549263.UserID", "UN93446014690826653");
Deleted : user_pref("CT2549263.ValidationData_Search", 0);
Deleted : user_pref("CT2549263.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2549263.alertChannelId", "942243");
Deleted : user_pref("CT2549263.backendstorage./9b+7e+x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e,x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e-x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e.x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e/x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e06cg5el8:", "6E6D6C726F6B6E6F7578");
Deleted : user_pref("CT2549263.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A74737278757174757B7E242F4B4947[...]
Deleted : user_pref("CT2549263.backendstorage./9b+7e0x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e1x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e2x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e3x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e4x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e5x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e6x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e7x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e8x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e9x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e:x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e;x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e<x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e=x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e>x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e?x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7e@x305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7eax305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Deleted : user_pref("CT2549263.backendstorage./9b+7ebx305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7ecx305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7edx305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b+7etx305", "2423");
Deleted : user_pref("CT2549263.backendstorage./9b-0?3g>d", "6E3A3D3D3D41756D7A46787A47204C4A7D7E2522507C232A22[...]
Deleted : user_pref("CT2549263.backendstorage./9b-0?3g@6:5;", "");
Deleted : user_pref("CT2549263.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Deleted : user_pref("CT2549263.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
Deleted : user_pref("CT2549263.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484777213F3E484F4E4D464[...]
Deleted : user_pref("CT2549263.backendstorage./9b5ba==9cjag", "6D3B3F3F6D6B6C437A6F457445474B777D7E7E794D");
Deleted : user_pref("CT2549263.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6C706F6C6E707673727372");
Deleted : user_pref("CT2549263.backendstorage./9b9643g3/9e", "6A");
Deleted : user_pref("CT2549263.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
Deleted : user_pref("CT2549263.backendstorage./9b<:222h64<", "393F352F3E");
Deleted : user_pref("CT2549263.backendstorage./9b<:222h64<l8daj", "6D7070707673757976712A7973727C79757E22");
Deleted : user_pref("CT2549263.backendstorage./9b=+03eh8h8j?:", "4443");
Deleted : user_pref("CT2549263.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Deleted : user_pref("CT2549263.backendstorage./9b?b0d:8aj62<h", "6D");
Deleted : user_pref("CT2549263.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Deleted : user_pref("CT2549263.backendstorage.cb_experience_000", "3239");
Deleted : user_pref("CT2549263.backendstorage.cb_user_id_000", "4342363130323234353638375F46697265666F78");
Deleted : user_pref("CT2549263.backendstorage.cbcountry_001", "435A");
Deleted : user_pref("CT2549263.backendstorage.cbfirsttime", "576564204F637420313020323031322031303A31313A30342[...]
Deleted : user_pref("CT2549263.backendstorage.gk_hsselite_notif_sent", "73656E74");
Deleted : user_pref("CT2549263.backendstorage.installationdate0.2690270998198123", "31333439313539383833343933[...]
Deleted : user_pref("CT2549263.backendstorage.printitgreenstatus", "74727565");
Deleted : user_pref("CT2549263.backendstorage.toolbarappheartbeat", "7B22223A313334393135393838333337387D");
Deleted : user_pref("CT2549263.backendstorage.toolbarnotificationqueue", "5B7B22617070223A302E3236393032373039[...]
Deleted : user_pref("CT2549263.backendstorage.toolbarnotificationsettings", "7B2273656E644E6F74696669636174696[...]
Deleted : user_pref("CT2549263.backendstorage.toolbarnotificationuserid", "3639373436363531343732");
Deleted : user_pref("CT2549263.backendstorage.url_history0001", "687474703A2F2F7777772E676F6F676C652E637A2F757[...]
Deleted : user_pref("CT2549263.components.1000080", true);
Deleted : user_pref("CT2549263.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2549263.globalFirstTimeInfoLastCheckTime", "Thu Jul 07 2011 21:18:21 GMT+0200");
Deleted : user_pref("CT2549263.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2549263.initDone", true);
Deleted : user_pref("CT2549263.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2549263.myStuffEnabled", true);
Deleted : user_pref("CT2549263.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2549263.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2549263.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2549263.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2549263.oldAppsList", "129118270998274454,129118270998586956,129167878631062901,1291182[...]
Deleted : user_pref("CT2549263.revertSettingsEnabled", true);
Deleted : user_pref("CT2549263.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2549263.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2549263.testingCtid", "");
Deleted : user_pref("CT2549263.toolbarAppMetaDataLastCheckTime", "Sat Mar 30 2013 16:14:00 GMT+0100");
Deleted : user_pref("CT2549263.toolbarContextMenuLastCheckTime", "Wed Jul 06 2011 23:07:52 GMT+0200");
Deleted : user_pref("CT2549263.usagesFlag", 2);
Deleted : user_pref("CT3176921.1000082.isPlayDisplay", "true");
Deleted : user_pref("CT3176921.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description[...]
Deleted : user_pref("CT3176921.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3176921.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"tru[...]
Deleted : user_pref("CT3176921.FF19Solved", "true");
Deleted : user_pref("CT3176921.FirstTime", "true");
Deleted : user_pref("CT3176921.FirstTimeFF3", "true");
Deleted : user_pref("CT3176921.PG_ENABLE", "dHJ1ZQ==");
Deleted : user_pref("CT3176921.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT317[...]
Deleted : user_pref("CT3176921.TopHitsConfig.enc", "ew0KICAgICJzcHJpdGVVcmwiOiAiaHR0cDovL3N0b3JhZ2UuY29uZHVpdC[...]
Deleted : user_pref("CT3176921.UserID", "UN62743415169533271");
Deleted : user_pref("CT3176921.addressBarTakeOverEnabledInHidden", "true");
Deleted : user_pref("CT3176921.autoDisableScopes", -1);
Deleted : user_pref("CT3176921.browser.search.defaultthis.engineName", "true");
Deleted : user_pref("CT3176921.defaultSearch", "true");
Deleted : user_pref("CT3176921.enableAlerts", "always");
Deleted : user_pref("CT3176921.enableFix404ByUser", "FALSE");
Deleted : user_pref("CT3176921.enableSearchFromAddressBar", "true");
Deleted : user_pref("CT3176921.firstTimeDialogOpened", "true");
Deleted : user_pref("CT3176921.fixPageNotFoundError", "true");
Deleted : user_pref("CT3176921.fixPageNotFoundErrorByUser", "true");
Deleted : user_pref("CT3176921.fixPageNotFoundErrorInHidden", "true");
Deleted : user_pref("CT3176921.fixUrls", true);
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_absolutelyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_azlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_bollywoodlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_cowboylyrics.org.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_darklyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_elyrics.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_hindilyrix.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_hitslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_leoslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_letssingit.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyred.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricinterpretations.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyrics-p.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsdepot.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsfind.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsfreak.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsmania.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsmode.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsocean.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsondemand.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsoverload.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_lyricsplanet.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_metrolyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_mp3lyrics.org.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_nomorelyrics.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_oldielyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_onlylyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_plyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_rapgenius.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_songlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_songmeanings.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_stlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_sweetslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_thelyricarchive.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_uplyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_last_targeted_visit_urbanlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_absolutelyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_azlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_bollywoodlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_cowboylyrics.org.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_darklyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_elyrics.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_hindilyrix.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_hitslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_leoslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_letssingit.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyred.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricinterpretations.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyrics-p.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsdepot.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsfind.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsfreak.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsmania.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsmode.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsocean.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsondemand.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsoverload.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_lyricsplanet.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_metrolyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_mp3lyrics.org.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_nomorelyrics.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_oldielyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_onlylyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_plyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_rapgenius.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_songlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_songmeanings.net.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_stlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_sweetslyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_thelyricarchive.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_uplyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_post_urls_urbanlyrics.com.enc", "bnVsbA==");
Deleted : user_pref("CT3176921.harvest_recent.enc", "W1siaHR0cDovL3d3dy5nb29nbGUuY3ovdXJsP3NhPXQmcmN0PWomcT0mZ[...]
Deleted : user_pref("CT3176921.homepageuserchanged", true);
Deleted : user_pref("CT3176921.installDate", "1/3/2013 19:35:38");
Deleted : user_pref("CT3176921.installId", "stub.exe");
Deleted : user_pref("CT3176921.installType", "conduitnsisintegration");
Deleted : user_pref("CT3176921.isCheckedStartAsHidden", true);
Deleted : user_pref("CT3176921.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3176921.isFirstTimeToolbarLoading", "false");
Deleted : user_pref("CT3176921.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Deleted : user_pref("CT3176921.keyword", "true");
Deleted : user_pref("CT3176921.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit[...]
Deleted : user_pref("CT3176921.lastVersion", "10.15.0.562");
Deleted : user_pref("CT3176921.mam_gk_AdOptimizer_appState.enc", "b24=");
Deleted : user_pref("CT3176921.mam_gk_Coming_Up_Next_appState.enc", "b24=");
Deleted : user_pref("CT3176921.mam_gk_CouponBuddy_appState.enc", "b24=");
Deleted : user_pref("CT3176921.mam_gk_PriceGong_appState.enc", "b24=");
Deleted : user_pref("CT3176921.mam_gk_appStateReportTime.enc", "MTM2MjE3NzQ4Nzg0Ng==");
Deleted : user_pref("CT3176921.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9w[...]
Deleted : user_pref("CT3176921.mam_gk_appsDefaultEnabled.enc", "dHJ1ZQ==");
Deleted : user_pref("CT3176921.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IkNvdXBvbkJ1ZGR5Iiw[...]
Deleted : user_pref("CT3176921.mam_gk_currentVersion.enc", "MS40LjMuMQ==");
Deleted : user_pref("CT3176921.mam_gk_first_time.enc", "MQ==");
Deleted : user_pref("CT3176921.mam_gk_installer_preapproved.enc", "dHJ1ZQ==");
Deleted : user_pref("CT3176921.mam_gk_lastLoginTime.enc", "MTM2MjE3NzQ4MzY5OQ==");
Deleted : user_pref("CT3176921.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50[...]
Deleted : user_pref("CT3176921.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
Deleted : user_pref("CT3176921.mam_gk_settings1.4.3.1.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVyd[...]
Deleted : user_pref("CT3176921.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
Deleted : user_pref("CT3176921.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Deleted : user_pref("CT3176921.mam_gk_userId.enc", "OTRhOTI5YTQtY2RiNy00NTgyLWFmMmQtYjBjNzliZTE0OThl");
Deleted : user_pref("CT3176921.mam_gk_user_apps_selection.enc", "");
Deleted : user_pref("CT3176921.migrateAppsAndComponents", true);
Deleted : user_pref("CT3176921.myThings_app_locale.enc", "Q1o=");
Deleted : user_pref("CT3176921.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fforum.viry.cz%2F[...]
Deleted : user_pref("CT3176921.openThankYouPage", "false");
Deleted : user_pref("CT3176921.openUninstallPage", "true");
Deleted : user_pref("CT3176921.revertSettingsEnabled", "false");
Deleted : user_pref("CT3176921.sac-periodic-reports.enc", "eyJ5dHRfcGluZ18wIjpbMTM2MjE3Mjk1ODI2NCwxNDQwMDAwMF1[...]
Deleted : user_pref("CT3176921.sac-user-ab-groups.enc", "eyJmZWVkIjo4OCwiaG92ZXJfZWZmZWN0Ijo2NSwiY2FsbF90b19hY[...]
Deleted : user_pref("CT3176921.sac-user-id.enc", "ImVhYzhhZDc1LTBkZTctNDE3Zi1hYjA3LWU4MmUwYzBmMzlhMiI=");
Deleted : user_pref("CT3176921.sac-yt-first-ping.enc", "MTM2MjE3Mjk1ODE5Mg==");
Deleted : user_pref("CT3176921.search.searchAppId", "10000002");
Deleted : user_pref("CT3176921.search.searchCount", "0");
Deleted : user_pref("CT3176921.searchFromAddressBarEnabledByUser", "true");
Deleted : user_pref("CT3176921.searchInNewTabEnabledByUser", "true");
Deleted : user_pref("CT3176921.searchInNewTabEnabledInHidden", "true");
Deleted : user_pref("CT3176921.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Deleted : user_pref("CT3176921.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Deleted : user_pref("CT3176921.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Deleted : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Deleted : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Deleted : user_pref("CT3176921.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Deleted : user_pref("CT3176921.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1362163071788");
Deleted : user_pref("CT3176921.serviceLayer_services_appsMetadata_lastUpdate", "1362163070863");
Deleted : user_pref("CT3176921.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1362163070926");
Deleted : user_pref("CT3176921.serviceLayer_services_location_lastUpdate", "1364591993181");
Deleted : user_pref("CT3176921.serviceLayer_services_login_10.14.65.43_lastUpdate", "1364118204512");
Deleted : user_pref("CT3176921.serviceLayer_services_login_10.15.0.562_lastUpdate", "1364668879918");
Deleted : user_pref("CT3176921.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1362163071315");
Deleted : user_pref("CT3176921.serviceLayer_services_searchAPI_lastUpdate", "1362163068039");
Deleted : user_pref("CT3176921.serviceLayer_services_serviceMap_lastUpdate", "1364591992662");
Deleted : user_pref("CT3176921.serviceLayer_services_setupAPI_lastUpdate", "1362163068874");
Deleted : user_pref("CT3176921.serviceLayer_services_toolbarContextMenu_lastUpdate", "1362163070545");
Deleted : user_pref("CT3176921.serviceLayer_services_toolbarSettings_lastUpdate", "1364668882888");
Deleted : user_pref("CT3176921.serviceLayer_services_translation_lastUpdate", "1364591995045");
Deleted : user_pref("CT3176921.settingsINI", true);
Deleted : user_pref("CT3176921.shouldFirstTimeDialog", "false");
Deleted : user_pref("CT3176921.showToolbarPermission", "false");
Deleted : user_pref("CT3176921.smartbar.CTID", "CT3176921");
Deleted : user_pref("CT3176921.smartbar.Uninstall", "0");
Deleted : user_pref("CT3176921.smartbar.homepage", true);
Deleted : user_pref("CT3176921.smartbar.isHidden", true);
Deleted : user_pref("CT3176921.smartbar.toolbarName", "express-files ");
Deleted : user_pref("CT3176921.startPage", "true");
Deleted : user_pref("CT3176921.toolbarBornServerTime", "1-3-2013");
Deleted : user_pref("CT3176921.toolbarCurrentServerTime", "30-3-2013");
Deleted : user_pref("CT3176921.toolbarLoginClientTime", "Mon Mar 25 2013 13:10:43 GMT+0100");
Deleted : user_pref("CT3176921.url_history0001.enc", "aHR0cDovL2xvZ2luLnN6bi5jei8/c2VydmljZUlkPWxpZGUmbG9nZ2Vk[...]
Deleted : user_pref("CT3176921.ytt-mam-test-ol-ts.enc", 671925469);
Deleted : user_pref("CT3176921.ytt-mam-test-uid-ol.enc", "YWFmMzU1MzItMDY0MS00OWIzLWI1ZTEtYjVjZDA3ZTgxYjRk");
Deleted : user_pref("CT3176921_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2549263/CT2549263[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/UK", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/942243/938027/UK", "\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2549263", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2549263",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2549263/CT2549263[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"[...]
Deleted : user_pref("CommunityToolbar.EngineHiddenByUser", true);
Deleted : user_pref("CommunityToolbar.EngineOwner", "");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "{a060276a-53be-45ec-8ebe-b94b1e803179}");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "expat_shield");
Deleted : user_pref("CommunityToolbar.IsEngineShown", false);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2549263");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{a060276a-53be-45ec-8ebe-b94b1e803179}");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "expat_shield");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.avg.com/route/?d=4b4a3a57&[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2549263");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2549263");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Feb 13 2012 01:56:23 GMT+01[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Wed Apr 18 2012 11:44:40 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Apr 18 2012 11:44:29 GMT+0200");
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "761e5e9e-5484-4fa0-a775-cf472bc45c28");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Thu Jul 07 2011 23:07:53 GMT+0200");
Deleted : user_pref("CommunityToolbar.globalUserId", "b211da13-d7d8-4c0c-b950-def3040f6169");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2549263");
Deleted : user_pref("CommunityToolbar.killedEngine", true);
Deleted : user_pref("CommunityToolbar.undefined", "");
Deleted : user_pref("Smartbar.ConduitHomepagesList", "");
Deleted : user_pref("Smartbar.ConduitSearchEngineList", "express-files Customized Web Search");
Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3176921[...]
Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=C[...]
Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3176921");
Deleted : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Data aplikací\\AVG S[...]
Deleted : user_pref("avg.install.userSPSettings", "Ask.com");
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultthis.engineName", "express-files Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3176921&Sea[...]
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("browser.search.selectedEngine", "express-files Customized Web Search");
Deleted : user_pref("extensions.plugin2@gameplaylabs.com.fr", "1301772315");
Deleted : user_pref("extensions.plugin2@gameplaylabs.com.ranonce", true);
Deleted : user_pref("extensions.plugin2@gameplaylabs.com.rule_/", "1301772335");
Deleted : user_pref("extensions.plugin2@gameplaylabs.com.rule_h", "1301772335");
Deleted : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3176921&SearchSource=2&CU[...]
Deleted : user_pref("smartBar.searchInNewTabOwner", "CT3176921");
Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3176921&octid=CT3176921[...]
Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[...]
Deleted : user_pref("smartbar.machineId", "77UD6TD1GATI39QUYXQ6C8SKKPNAPKI40CD88WTEALONB9KBJBOB441OYQUTVHRDNWJ[...]
Deleted : user_pref("smartbar.originalHomepage", "hxxp://www.seznam.cz/");
Deleted : user_pref("smartbar.originalSearchAddressUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT254[...]
Deleted : user_pref("smartbar.originalSearchEngine", "Ask.com");

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\Verča\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [46332 octets] - [30/03/2013 20:28:19]
AdwCleaner[R2].txt - [46393 octets] - [30/03/2013 20:30:02]
AdwCleaner[S1].txt - [47164 octets] - [30/03/2013 20:50:45]

########## EOF - C:\AdwCleaner[S1].txt - [47225 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#10 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#11 Příspěvek od ver3 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Verča at 2013-03-30 21:09:01
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 19 GB (26%) free of 74 GB
Total RAM: 1015 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:09:13, on 30.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ExpressFiles\EFUpdater.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Verča\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Verča.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: GamePlayLabsBHO - {984A9162-8891-4D19-8CFE-17648BB4E1EC} - C:\Documents and Settings\Verča\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe

--
End of file - 9143 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\Express FilesUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\ROC_JAN2013_TB_rmv.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, fbp@fbpurity.com:6.1.1, engine@conduit.com:3.3.3.2, {a060276a-53be-45ec-8ebe-b94b1e803179}:3.8.1.0, toolbar@ask.com:3.14.0.100010, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.2124, {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2126, avg@toolbar:10.2.0.3, {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
lastfm-compatibility-percentage.user.js
sprotector.js

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
answers.xml
avg_igeared.xml
bing.xml
creativecommons.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-30 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class - C:\Documents and Settings\Verča\Local Settings\Data aplikací\GamePlayLabs Plugin\BHO.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-04-15 1164680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-30 170912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-04-27 17881088]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2009-04-16 630784]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2009-03-13 98304]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2009-04-16 118784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-04-09 1512744]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-04-09 79144]
"LiveUpdate"=C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [2009-06-25 712704]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-27 585728]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-07-27 397312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe

C:\Documents and Settings\Verča\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"="C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\ExpressFiles\expressdl.exe"="C:\Program Files\ExpressFiles\expressdl.exe:*:Enabled:Express Files"
"C:\Program Files\ExpressFiles\ExpressFiles.exe"="C:\Program Files\ExpressFiles\ExpressFiles.exe:*:Enabled:Express Files"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2013-03-30 20:50:45 ----A---- C:\AdwCleaner[S1].txt
2013-03-30 20:30:02 ----A---- C:\AdwCleaner[R2].txt
2013-03-30 20:28:19 ----A---- C:\AdwCleaner[R1].txt
2013-03-30 15:55:13 ----D---- C:\Program Files\trend micro
2013-03-30 15:55:12 ----D---- C:\rsit
2013-03-30 03:02:08 ----A---- C:\WINDOWS\system32\javaws.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\javaw.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\java.exe
2013-03-25 21:39:46 ----A---- C:\WINDOWS\system32\GPhotos.scr
2013-03-16 03:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2013-03-12 20:29:05 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2013-03-09 12:20:42 ----D---- C:\WINDOWS\Minidump
2013-03-09 01:46:08 ----D---- C:\WINDOWS\system32\NtmsData
2013-03-08 12:59:18 ----D---- C:\Program Files\Mozilla Firefox
2013-03-01 19:33:09 ----D---- C:\Program Files\ExpressFiles
2013-03-01 19:33:09 ----D---- C:\Documents and Settings\Verča\Data aplikací\ExpressFiles

======List of files/folders modified in the last 1 month======

2013-03-30 20:52:12 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-03-30 20:50:59 ----RD---- C:\Program Files
2013-03-30 20:26:16 ----D---- C:\WINDOWS\Prefetch
2013-03-30 19:33:06 ----D---- C:\WINDOWS\Temp
2013-03-30 18:35:17 ----D---- C:\WINDOWS\system32
2013-03-30 18:34:44 ----D---- C:\WINDOWS\system32\CatRoot2
2013-03-30 15:35:26 ----D---- C:\WINDOWS\system32\drivers
2013-03-30 12:23:21 ----D---- C:\WINDOWS\SHELLNEW
2013-03-30 12:23:19 ----D---- C:\WINDOWS\I386
2013-03-30 10:11:52 ----D---- C:\WINDOWS\Registration
2013-03-30 03:02:40 ----SHD---- C:\WINDOWS\Installer
2013-03-30 03:02:40 ----HD---- C:\Config.Msi
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-03-30 03:01:19 ----D---- C:\Program Files\Java
2013-03-30 01:33:22 ----HD---- C:\WINDOWS\inf
2013-03-30 00:45:32 ----D---- C:\WINDOWS
2013-03-29 20:45:04 ----D---- C:\Documents and Settings\Verča\Data aplikací\AIMP
2013-03-25 12:25:47 ----SHD---- C:\System Volume Information
2013-03-16 03:02:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-03-16 03:01:26 ----HD---- C:\WINDOWS\$hf_mig$
2013-03-14 03:02:31 ----A---- C:\WINDOWS\system32\MRT.exe
2013-03-14 03:02:23 ----A---- C:\WINDOWS\imsins.BAK
2013-03-14 03:01:53 ----D---- C:\Program Files\Internet Explorer
2013-03-14 03:01:34 ----D---- C:\WINDOWS\ie8updates
2013-03-12 20:29:12 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-03-09 11:01:43 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Temp
2013-03-09 10:59:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2013-03-09 10:58:00 ----D---- C:\Program Files\Common Files
2013-03-09 10:57:24 ----D---- C:\WINDOWS\system32\drivers\AVG
2013-03-09 10:50:34 ----D---- C:\Program Files\DsNET Corp
2013-03-09 10:49:12 ----SD---- C:\WINDOWS\Tasks
2013-03-09 01:46:06 ----D---- C:\WINDOWS\repair
2013-03-09 00:52:34 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-08 22:31:31 ----D---- C:\Documents and Settings\Verča\Data aplikací\BSplayer
2013-03-01 03:27:55 ----A---- C:\WINDOWS\system32\mshtml.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2008-09-12 327192]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-01 691696]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-04-27 5074944]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-03-02 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2009-07-10 1015424]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-09-10 27632]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-13 1759616]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2009-04-09 208816]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-29 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-29 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-29 21568]
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-09 24576]
S3 htcnprot;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-05-16 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2011-05-25 32768]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 uvclf;uvclf; C:\WINDOWS\system32\DRIVERS\uvclf.sys [2008-11-19 39040]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-03-30 170912]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 253656]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-08 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#12 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Skype\Toolbars
C:\Program Files\Windows Live\Toolbar
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#13 Příspěvek od ver3 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Verča at 2013-03-30 22:26:01
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 23 GB (31%) free of 74 GB
Total RAM: 1015 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:26:07, on 30.3.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ExpressFiles\EFUpdater.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Documents and Settings\Verča\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Verča.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe

--
End of file - 8433 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\Express FilesUpdate.job
C:\WINDOWS\tasks\ROC_JAN2013_TB_rmv.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18, jqs@sun.com:1.0, {20a82645-c095-46ed-80e3-08825760534b}:1.2.1, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, fbp@fbpurity.com:6.1.1, engine@conduit.com:3.3.3.2, {a060276a-53be-45ec-8ebe-b94b1e803179}:3.8.1.0, toolbar@ask.com:3.14.0.100010, {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.2124, {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2126, avg@toolbar:10.2.0.3, {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.28"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.180 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
lastfm-compatibility-percentage.user.js
sprotector.js

C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
answers.xml
avg_igeared.xml
bing.xml
creativecommons.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}

C:\Documents and Settings\Verča\Data aplikací\Mozilla\Firefox\Profiles\jagrp2z2.default\searchplugins\
qipsearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-30 461216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-30 170912]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-04-27 17881088]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2009-04-16 630784]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2009-03-13 98304]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2009-04-16 118784]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-04-09 1512744]
"SynAsusAcpi"=C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [2009-04-09 79144]
"LiveUpdate"=C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [2009-06-25 712704]
"HTC Sync Loader"=C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-01-27 585728]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Eee Docking"=C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [2009-07-27 397312]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe

C:\Documents and Settings\Verča\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=255

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"="C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\ExpressFiles\expressdl.exe"="C:\Program Files\ExpressFiles\expressdl.exe:*:Enabled:Express Files"
"C:\Program Files\ExpressFiles\ExpressFiles.exe"="C:\Program Files\ExpressFiles\ExpressFiles.exe:*:Enabled:Express Files"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
"C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe"="C:\Documents and Settings\Verča\Local Settings\Temp\7zS0C97\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll

======List of files/folders created in the last 1 month======

2013-03-30 22:18:39 ----D---- C:\_OTM
2013-03-30 20:50:45 ----A---- C:\AdwCleaner[S1].txt
2013-03-30 20:30:02 ----A---- C:\AdwCleaner[R2].txt
2013-03-30 20:28:19 ----A---- C:\AdwCleaner[R1].txt
2013-03-30 15:55:13 ----D---- C:\Program Files\trend micro
2013-03-30 15:55:12 ----D---- C:\rsit
2013-03-30 03:02:08 ----A---- C:\WINDOWS\system32\javaws.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\javaw.exe
2013-03-30 03:01:53 ----A---- C:\WINDOWS\system32\java.exe
2013-03-25 21:39:46 ----A---- C:\WINDOWS\system32\GPhotos.scr
2013-03-16 03:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2013-03-12 20:29:05 ----A---- C:\WINDOWS\system32\FlashPlayerInstaller.exe
2013-03-09 12:20:42 ----D---- C:\WINDOWS\Minidump
2013-03-09 01:46:08 ----D---- C:\WINDOWS\system32\NtmsData
2013-03-08 12:59:18 ----D---- C:\Program Files\Mozilla Firefox
2013-03-01 19:33:09 ----D---- C:\Program Files\ExpressFiles
2013-03-01 19:33:09 ----D---- C:\Documents and Settings\Verča\Data aplikací\ExpressFiles

======List of files/folders modified in the last 1 month======

2013-03-30 22:25:28 ----D---- C:\WINDOWS\Prefetch
2013-03-30 22:22:58 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-03-30 22:22:29 ----D---- C:\WINDOWS\Temp
2013-03-30 22:21:32 ----D---- C:\WINDOWS\system32
2013-03-30 22:18:41 ----SD---- C:\WINDOWS\Tasks
2013-03-30 22:18:41 ----RD---- C:\Program Files\Skype
2013-03-30 22:18:41 ----D---- C:\Program Files\Windows Live
2013-03-30 20:50:59 ----RD---- C:\Program Files
2013-03-30 18:34:44 ----D---- C:\WINDOWS\system32\CatRoot2
2013-03-30 15:35:26 ----D---- C:\WINDOWS\system32\drivers
2013-03-30 12:23:21 ----D---- C:\WINDOWS\SHELLNEW
2013-03-30 12:23:19 ----D---- C:\WINDOWS\I386
2013-03-30 10:11:52 ----D---- C:\WINDOWS\Registration
2013-03-30 03:02:40 ----SHD---- C:\WINDOWS\Installer
2013-03-30 03:02:40 ----HD---- C:\Config.Msi
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2013-03-30 03:01:27 ----A---- C:\WINDOWS\system32\deployJava1.dll
2013-03-30 03:01:19 ----D---- C:\Program Files\Java
2013-03-30 01:33:22 ----HD---- C:\WINDOWS\inf
2013-03-30 00:45:32 ----D---- C:\WINDOWS
2013-03-29 20:45:04 ----D---- C:\Documents and Settings\Verča\Data aplikací\AIMP
2013-03-25 12:25:47 ----SHD---- C:\System Volume Information
2013-03-16 03:02:10 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-03-16 03:01:26 ----HD---- C:\WINDOWS\$hf_mig$
2013-03-14 03:02:31 ----A---- C:\WINDOWS\system32\MRT.exe
2013-03-14 03:02:23 ----A---- C:\WINDOWS\imsins.BAK
2013-03-14 03:01:53 ----D---- C:\Program Files\Internet Explorer
2013-03-14 03:01:34 ----D---- C:\WINDOWS\ie8updates
2013-03-12 20:29:12 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2013-03-09 11:01:43 ----AD---- C:\Documents and Settings\All Users\Data aplikací\Temp
2013-03-09 10:59:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2013-03-09 10:58:00 ----D---- C:\Program Files\Common Files
2013-03-09 10:57:24 ----D---- C:\WINDOWS\system32\drivers\AVG
2013-03-09 10:50:34 ----D---- C:\Program Files\DsNET Corp
2013-03-09 01:46:06 ----D---- C:\WINDOWS\repair
2013-03-09 00:52:34 ----D---- C:\Program Files\Mozilla Maintenance Service
2013-03-08 22:31:31 ----D---- C:\Documents and Settings\Verča\Data aplikací\BSplayer
2013-03-01 03:27:55 ----A---- C:\WINDOWS\system32\mshtml.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\WINDOWS\system32\drivers\iaStor.sys [2008-09-12 327192]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-01 691696]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-04-27 5074944]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-03-02 38912]
R3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2009-07-10 1015424]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-09-10 27632]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\WINDOWS\system32\DRIVERS\snp2uvc.sys [2009-03-13 1759616]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2009-04-09 208816]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys []
S3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys []
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys []
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-29 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-29 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-29 21568]
S3 HTCAND32;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-06-09 24576]
S3 htcnprot;HTC NDIS Protocol Driver; C:\WINDOWS\system32\DRIVERS\htcnprot.sys [2010-06-22 21248]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2010-05-16 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2011-05-25 32768]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 uvclf;uvclf; C:\WINDOWS\system32\DRIVERS\uvclf.sys [2008-11-19 39040]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-03-30 170912]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [2011-09-15 88576]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-12 253656]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-01-21 136176]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-03-08 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119488
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Modrá obrazovka

#14 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\Verča.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

ver3
Návštěvník
Návštěvník
Příspěvky: 79
Registrován: 30 bře 2013 01:20

Re: Modrá obrazovka

#15 Příspěvek od ver3 »

Hotovo. Moc děkuji.
Nyní mohu opět nainstalovat Aviru?

Zamčeno