Zde je výsledek:
ComboFix 13-06-30.01 - PLANEO 01.07.2013 21:55:10.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3070.1584 [GMT 2:00]
Spuštěný z: c:\users\PLANEO\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\users\PLANEO\Desktop\CFScript.txt..txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
file zipped: c:\windows\system32\acovcnt.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Conduit
c:\program files\Conduit\Community Alerts\Alert.dll
c:\program files\DivX_Browser_Bar
c:\program files\DivX_Browser_Bar\DivX_Browser_BarToolbarHelper.exe
c:\program files\DivX_Browser_Bar\GottenAppsContextMenu.xml
c:\program files\DivX_Browser_Bar\hk64tbDivX.dll
c:\program files\DivX_Browser_Bar\hktbDivX.dll
c:\program files\DivX_Browser_Bar\ldrtbDivX.dll
c:\program files\DivX_Browser_Bar\OtherAppsContextMenu.xml
c:\program files\DivX_Browser_Bar\prxtbDivX.dll
c:\program files\DivX_Browser_Bar\SharedAppsContextMenu.xml
c:\program files\DivX_Browser_Bar\tbDivX.dll
c:\program files\DivX_Browser_Bar\toolbar.cfg
c:\program files\DivX_Browser_Bar\ToolbarContextMenu.xml
c:\program files\DivX_Browser_Bar\uninstall.exe
c:\program files\Google\GoogleToolbarNotifier
c:\program files\Google\GoogleToolbarNotifier\5.7.8313.1002\gth.dll
c:\program files\Google\GoogleToolbarNotifier\5.7.8313.1002\gtn.dll
c:\program files\Google\GoogleToolbarNotifier\5.7.8313.1002\Readme.url
c:\program files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\programdata\Conduit
c:\programdata\Conduit\conduitutil.exe
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(10)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(12)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(14)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(21)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(4)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(52)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(7)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(8)\WLID_USERTILE.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\AUTHAPP_HEADER.JPG
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\DOWNARROW00.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1025.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1028.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1037.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1038.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1041.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1042.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1081.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1095.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1097.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1099.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1100.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_1102.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_2052.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_3098.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\GLOBAL_DEFAULT.CSS
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\HIP_ABC.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\HIP_AUDIOREPL.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\HIP_SPEAKER.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\HIPUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\IC_ALERT_LOW_16X.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\MULTIUSERSSO.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\NEWUSER.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\NEWUSERFED.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\SAVEDUSERS.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WAIT.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WAITPAGE.HTM
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WLID_BOOK.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WLID_FRAME.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WLID_ICON_ERROR.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WLID_LOGO_H.GIF
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(9)\WLID_USERTILE.GIF
c:\users\PLANEO\AppData\Roaming\SearchProtect
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\cltmng.exe
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\ChromeModule.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\msvcp100.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\msvcr100.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\rep.dat
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\SPHook32.dll
c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\SPRunner.exe
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\dialogsApi.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\lib\jquery.min.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\lib\json2.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.css
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\bubble.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\images\information.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-LTR.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-default-RTL.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-LTR.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\images\x-mouseover-RTL.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spbd\main.html
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\images\ok-button.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\images\separation-line.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\images\warning.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\main.html
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\SearchProtector.css
c:\users\PLANEO\AppData\Roaming\SearchProtect\Dialogs\spsd\settings.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\abstraction.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\application.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\dialogsApi.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\jquery.min.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib\json2.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.css
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\bubble.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\information.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-LTR.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-RTL.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-LTR.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-RTL.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\main.html
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\ok-button.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\separation-line.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images\warning.png
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\main.html
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\SearchProtector.css
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\settings.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\nsprotector.js
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\popupTransparent.xul
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\EN
c:\users\PLANEO\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository\searchProtectorData
c:\programdata\Microsoft\IdentityCRL\production\temp . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\AUTHAPP_HEADER.JPG . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DOWNARROW00.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1025.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1028.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1037.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1038.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1041.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1042.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1081.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1095.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1097.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1098.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1099.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1100.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_1102.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_2052.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_3098.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\GLOBAL_DEFAULT.CSS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\HIP_ABC.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\HIP_AUDIOREPL.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\HIP_SPEAKER.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\HIPUSER.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IC_ALERT_LOW_16X.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\MULTIUSERSSO.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSER.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERFED.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSERS.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WAIT.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WAITPAGE.HTM . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WLID_BOOK.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WLID_FRAME.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WLID_ICON_ERROR.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WLID_LOGO_H.GIF . . . . nemohl být smazán
c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\WLID_USERTILE.GIF . . . . nemohl být smazán
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-06-01 do 2013-07-01 )))))))))))))))))))))))))))))))
.
.
2013-07-01 20:17 . 2013-07-01 20:17 -------- d-----w- c:\users\PLANEO\AppData\Roaming\SearchProtect
2013-07-01 20:09 . 2013-07-01 20:17 -------- d-----w- c:\users\PLANEO\AppData\Local\temp
2013-07-01 20:09 . 2013-07-01 20:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-01 16:59 . 2013-07-01 16:59 -------- d-----w- c:\program files\SUPERAntiSpyware
2013-07-01 16:58 . 2013-07-01 16:58 -------- d-----w- c:\users\PLANEO\AppData\Roaming\SUPERAntiSpyware.com
2013-07-01 14:50 . 2013-07-01 17:43 -------- d-----w- c:\program files\trend micro
2013-07-01 14:50 . 2013-07-01 17:12 -------- d-----w- C:\rsit
2013-07-01 13:22 . 2013-07-01 13:22 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2013-07-01 12:59 . 2013-07-01 12:59 -------- d-----w- c:\users\Asined
2013-06-29 23:11 . 2013-06-29 23:11 -------- d-----w- c:\program files\Bonjour
2013-06-28 23:08 . 2013-06-12 04:18 7068072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E87AD040-FD57-4927-B976-EE61C89AB78A}\mpengine.dll
2013-06-25 23:49 . 2013-06-29 23:14 -------- d-----w- c:\program files\Safari
2013-06-24 07:26 . 2013-06-25 23:50 -------- d-----w- c:\users\PLANEO\AppData\Roaming\Apple Computer
2013-06-23 13:33 . 2013-06-23 13:34 -------- d-----w- c:\program files\CCleaner
2013-06-23 12:44 . 2013-06-23 12:42 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-23 12:44 . 2013-06-23 12:42 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-23 12:43 . 2013-06-23 12:43 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-23 12:39 . 2013-06-23 12:39 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2013-06-23 12:39 . 2013-06-23 12:39 159744 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin5.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin4.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
2013-06-23 12:39 . 2013-06-23 12:38 159744 ----a-w- c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
2013-06-23 11:49 . 2013-06-23 11:49 -------- d-----w- c:\users\PLANEO\AppData\Local\Conduit
2013-06-23 11:48 . 2013-06-23 11:48 -------- d-----w- c:\users\PLANEO\AppData\Local\CRE
2013-06-23 11:47 . 2013-06-23 11:47 -------- d-----w- c:\program files\SearchProtect
2013-06-23 11:45 . 2013-06-23 11:45 81768 ----a-w- C:\ministub.exe
2013-06-23 00:11 . 2013-06-23 00:11 -------- d-----w- c:\users\PLANEO\AppData\Roaming\Malwarebytes
2013-06-23 00:10 . 2013-06-23 00:10 -------- d-----w- c:\programdata\Malwarebytes
2013-06-13 17:17 . 2013-05-08 04:37 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-06-13 17:17 . 2013-05-02 04:04 443904 ----a-w- c:\windows\system32\win32spl.dll
2013-06-13 17:17 . 2013-05-02 04:03 37376 ----a-w- c:\windows\system32\printcom.dll
2013-06-13 17:16 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe
2013-06-13 17:16 . 2013-04-24 04:00 985600 ----a-w- c:\windows\system32\crypt32.dll
2013-06-13 17:16 . 2013-04-24 04:00 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-06-13 17:16 . 2013-04-24 04:00 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-06-13 17:16 . 2013-04-24 04:00 41984 ----a-w- c:\windows\system32\certenc.dll
2013-06-13 17:16 . 2013-05-02 22:03 3603832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-06-13 17:16 . 2013-05-02 22:03 3551096 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-13 17:15 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-01 20:13 . 2009-10-01 20:09 45056 ----a-w- c:\windows\system32\acovcnt.exe
2013-06-27 19:14 . 2013-04-21 09:50 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-27 19:14 . 2010-01-05 10:30 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-27 19:13 . 2011-10-25 06:02 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-24 09:24 . 2013-02-19 09:08 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-24 09:24 . 2012-11-03 11:40 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-09 08:59 . 2013-04-21 09:50 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2010-01-05 10:30 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2010-01-05 10:30 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-05-09 08:59 . 2010-01-05 10:30 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:59 . 2010-01-05 10:30 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:58 . 2011-10-25 06:01 41664 ----a-w- c:\windows\avastSS.scr
2013-05-09 08:58 . 2010-01-05 10:30 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-05-08 06:10 . 2011-06-11 00:58 421200 ----a-w- c:\windows\system32\msvcp100.dll
2013-05-02 00:06 . 2010-01-05 10:16 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 01:59 . 2013-05-01 01:59 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2013-05-01 01:59 . 2013-05-01 01:59 69632 ----a-w- c:\windows\system32\QuickTime.qts
2013-04-15 14:20 . 2013-05-15 16:51 638328 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-13 10:56 . 2013-05-15 16:51 37376 ----a-w- c:\windows\system32\cdd.dll
2013-04-09 01:36 . 2013-05-15 16:51 2049024 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"ICQ"="c:\program files\ICQ7.7\ICQ.exe" [2012-01-23 127040]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"EADM"="d:\origin\Origin.exe" [2013-06-04 3456080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-05-15 4760816]
"SearchProtect"="c:\users\PLANEO\AppData\Roaming\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-12 6265376]
"Skytel"="Skytel.exe" [2008-08-12 1833504]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"ExpressFiles"="c:\program files\ExpressFiles\ExpressFiles.exe" [2012-04-13 455800]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2013-03-29 295072]
"SearchProtectAll"="c:\program files\SearchProtect\bin\cltmng.exe" [2013-05-08 2852640]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-05-20 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888]
.
c:\users\PLANEO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-2-16 384512]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 115440]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
S0 Achernar;Achernar - SCSI Command Filter Drivers;c:\windows\System32\Drivers\Achernar.sys [2007-02-05 18432]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2013-05-23 119056]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-20 19:34 1165776 ----a-w- c:\program files\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-07-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-19 09:24]
.
2013-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 15:01]
.
2013-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 15:01]
.
2011-10-28 c:\windows\Tasks\WebReg Deskjet F2100 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-12-10 20:36]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3288691&octid=CT3288691&SearchSource=61&CUI=UN21897031020324405&UM=2&UP=SP938480DB-6D39-45C1-98B8-4AE31FB52974
mStart Page = hxxp://
www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 10.98.231.66 10.98.0.227
FF - ProfilePath - c:\users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - ExtSQL: 2013-06-23 13:46; {77e8143b-6759-416e-b521-82cfed75150b}; c:\users\PLANEO\AppData\Roaming\Mozilla\Firefox\Profiles\h9ndpdpu.default\extensions\{77e8143b-6759-416e-b521-82cfed75150b}
FF - ExtSQL: !HIDDEN! 2009-10-23 04:37; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109980
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 2e9ec95c00000000000000224351a545
FF - user.js: extensions.BabylonToolbar_i.hardId - 2e9ec95c00000000000000224351a545
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15443
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1711:31
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-DivX_Browser_Bar Toolbar - c:\program files\DivX_Browser_Bar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-07-01 22:16
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\SearchProtect\bin\CltMngSvc.exe
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\ASUS\SmartLogon\sensorsrv.exe
c:\program files\ATK Hotkey\Hcontrol.exe
c:\program files\ASUS\Net4Switch\Net4Switch.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\ATK Media\DMEDIA.EXE
c:\program files\ASUS\ATK Media\GPSWATCH.EXE
c:\program files\P4G\BatteryLife.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\ATK Hotkey\WDC.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Microsoft Office\Office12\ONENOTEM.EXE
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2013-07-01 22:25:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-07-01 20:25
ComboFix2.txt 2013-07-01 18:30
.
Před spuštěním: Volných bajtů: 27 325 276 160
Po spuštění: Volných bajtů: 34 169 073 664
.
- - End Of File - - D74577F730D870513B5A608CE31E5896
64B1E91C5C6C2157642651010728F90F
Nahr nˇ probŘhlo ŁspŘçnŘ