Stránka 1 z 1

Vypínání a blbnutí baterky u NB

Napsal: 23 čer 2014 09:57
od jasnenka
Ahoj,

mám podezření, jestli nemám někde hluboko nějakého viráka, protože se mi z ničeho nic vypíná NB a také blbne baterka, která je již koupená nová i s nabíječkou.

Logfile of random's system information tool 1.10 (written by random/random)
Run by marika at 2014-06-23 10:55:18
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 86 GB (63%) free of 137 GB
Total RAM: 1791 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:55:24, on 23.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\marika\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\marika.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com/406
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKCU\..\Run: [GUDelayStartup] "C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\marika\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\marika\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ashampoo HDD Control 2 Service (AHDDC2) - Unknown owner - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9259 bytes

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GlaryInitialize 5.job - C:\Program Files (x86)\Glary Utilities 5\Initialize.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/?clid=3"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.206 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\extensions\
avg@toolbar
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\searchplugins\
avg-secure-search.xml
firmycz.xml
mapycz.xml
Search_Results.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GUDelayStartup"=C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [2014-06-16 37152]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avas_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avss_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tpavdrw_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tpmgma_service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.VP60"=C:\windows\system32\vp6vfw.dll
"vidc.VP61"=C:\windows\system32\vp6vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-06-20 21:26:53 ----D---- C:\Users\marika\AppData\Roaming\JAM Software
2014-06-20 16:01:35 ----AD---- C:\Kaspersky Rescue Disk 10.0
2014-06-20 12:17:44 ----D---- C:\Users\marika\AppData\Roaming\Ashampoo
2014-06-20 12:17:19 ----D---- C:\ProgramData\Ashampoo
2014-06-19 10:59:20 ----N---- C:\bootsqm.dat
2014-06-11 13:26:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-11 11:36:43 ----A---- C:\windows\SysWOW64\msxml6.dll
2014-06-11 11:36:42 ----A---- C:\windows\SysWOW64\msxml6r.dll
2014-06-11 11:36:42 ----A---- C:\windows\SysWOW64\msxml3r.dll
2014-06-11 11:36:42 ----A---- C:\windows\SysWOW64\msxml3.dll
2014-06-11 11:36:37 ----A---- C:\windows\SysWOW64\usp10.dll
2014-06-11 11:36:34 ----A---- C:\windows\SysWOW64\mshtmled.dll
2014-06-11 11:36:34 ----A---- C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-11 11:36:33 ----A---- C:\windows\SysWOW64\urlmon.dll
2014-06-11 11:36:33 ----A---- C:\windows\SysWOW64\jscript9diag.dll
2014-06-11 11:36:32 ----A---- C:\windows\SysWOW64\mshtml.dll
2014-06-11 11:36:32 ----A---- C:\windows\SysWOW64\msfeeds.dll
2014-06-11 11:36:32 ----A---- C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 11:36:32 ----A---- C:\windows\SysWOW64\dxtmsft.dll
2014-06-11 11:36:30 ----A---- C:\windows\SysWOW64\iesetup.dll
2014-06-11 11:36:29 ----A---- C:\windows\SysWOW64\iertutil.dll
2014-06-11 11:36:28 ----A---- C:\windows\SysWOW64\jsproxy.dll
2014-06-11 11:36:28 ----A---- C:\windows\SysWOW64\iernonce.dll
2014-06-11 11:36:27 ----A---- C:\windows\SysWOW64\ieui.dll
2014-06-11 11:36:27 ----A---- C:\windows\SysWOW64\ieframe.dll
2014-06-11 11:36:27 ----A---- C:\windows\SysWOW64\dxtrans.dll
2014-06-11 11:36:24 ----A---- C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-11 11:36:23 ----A---- C:\windows\SysWOW64\vbscript.dll
2014-06-11 11:36:23 ----A---- C:\windows\SysWOW64\jscript9.dll
2014-06-11 11:36:23 ----A---- C:\windows\SysWOW64\ieUnatt.exe
2014-06-11 11:36:23 ----A---- C:\windows\SysWOW64\ieapfltr.dll
2014-06-11 11:36:22 ----A---- C:\windows\SysWOW64\wininet.dll
2014-06-11 11:36:21 ----A---- C:\windows\SysWOW64\msrating.dll
2014-06-05 06:39:13 ----A---- C:\BackupLoader.ini
2014-06-02 12:09:59 ----D---- C:\ProgramData\Lamantine
2014-05-26 10:47:06 ----D---- C:\Program Files (x86)\Common Files\Skype

======List of files/folders modified in the last 1 month======

2014-06-23 10:55:24 ----D---- C:\Program Files (x86)\trend micro
2014-06-23 10:51:37 ----D---- C:\windows\temp
2014-06-23 10:42:20 ----D---- C:\windows\SoftwareDistribution
2014-06-23 10:41:32 ----D---- C:\Windows
2014-06-23 10:41:26 ----D---- C:\windows\inf
2014-06-23 10:39:47 ----D---- C:\Program Files (x86)\Glary Utilities 5
2014-06-23 10:35:30 ----D---- C:\windows\System32
2014-06-23 10:27:48 ----D---- C:\windows\Minidump
2014-06-21 21:29:07 ----SHD---- C:\System Volume Information
2014-06-21 17:58:51 ----RD---- C:\Program Files (x86)
2014-06-21 17:58:26 ----RD---- C:\Program Files
2014-06-20 12:42:55 ----D---- C:\Users\marika\AppData\Roaming\Skype
2014-06-20 12:17:19 ----D---- C:\ProgramData
2014-06-20 12:16:12 ----D---- C:\Program Files (x86)\Ashampoo
2014-06-18 10:07:33 ----D---- C:\windows\Tasks
2014-06-18 09:50:19 ----D---- C:\Users\marika\AppData\Roaming\DiskDefrag
2014-06-14 15:37:23 ----D---- C:\windows\Prefetch
2014-06-13 09:39:23 ----D---- C:\windows\rescache
2014-06-12 12:49:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-11 13:29:44 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2014-06-11 12:06:43 ----D---- C:\windows\debug
2014-06-11 11:54:15 ----D---- C:\windows\winsxs
2014-06-11 11:48:46 ----D---- C:\windows\SysWOW64
2014-06-11 11:48:36 ----D---- C:\windows\SysWOW64\en-US
2014-06-11 11:48:27 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-11 11:42:34 ----SHD---- C:\windows\Installer
2014-06-11 11:42:33 ----D---- C:\Config.Msi
2014-06-11 11:42:32 ----D---- C:\ProgramData\Microsoft Help
2014-06-03 10:33:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-06-03 10:33:04 ----D---- C:\Program Files (x86)\Electronic Arts
2014-06-02 15:25:03 ----D---- C:\ProgramData\Origin
2014-06-02 12:10:15 ----D---- C:\Program Files (x86)\Sticky Password
2014-05-26 10:47:15 ----D---- C:\ProgramData\Skype
2014-05-26 10:47:06 ----RD---- C:\Program Files (x86)\Skype
2014-05-26 10:47:06 ----D---- C:\Program Files (x86)\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys []
R0 BootDefragDriver;BootDefragDriver; C:\windows\System32\drivers\BootDefragDriver.sys [2013-04-24 16640]
R0 GUBootStartup;GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys []
R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys []
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys []
R2 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys []
R3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys []
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys []
R3 RTHDMIAzAudService;Service for HDMI; C:\windows\system32\drivers\RtHDMIVX.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys []
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys []
S3 mvusbews;USB EWS Device; C:\windows\System32\Drivers\mvusbews.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys []
S3 RtsUIR;Realtek IR Driver; C:\windows\system32\DRIVERS\Rts516xIR.sys []
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys []
S3 smserial;smserial; C:\windows\system32\DRIVERS\SmSerl64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys []
S3 USBCCID;Realtek Smartcard Reader Driver; C:\windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys []
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AHDDC2;Ashampoo HDD Control 2 Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-04-05 1518976]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe []
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-07-31 67584]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192]
R2 HPSIService;HP SI Service; C:\windows\system32\HPSIsvc.exe []
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-04 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-28 257712]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 DfSdkS;Defragmentation-Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-04 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe /V []
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-11 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: Vypínání a blbnutí baterky u NB

Napsal: 23 čer 2014 16:22
od Rudy
Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Vypínání a blbnutí baterky u NB

Napsal: 25 čer 2014 10:55
od jasnenka
Provedla jsem a zasílám...

# AdwCleaner v3.213 - Report created 25/06/2014 at 11:45:58
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : marika - MARIKA-MSI
# Running from : C:\Users\marika\Downloads\adwcleaner_3.213.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\Users\marika\AppData\Local\Conduit
Folder Deleted : C:\Users\marika\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\marika\AppData\Local\PackageAware
Folder Deleted : C:\Users\marika\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\marika\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\marika\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\marika\AppData\Roaming\YourFileDownloader
Folder Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\ConduitCommon
Folder Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\ICQToolbarData
Folder Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\Extensions\Avg@toolbar
File Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\invalidprefs.js
File Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\searchplugins\avg-secure-search.xml
File Deleted : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\searchplugins\Search_Results.xml
File Deleted : C:\windows\System32\Tasks\YourFile Update

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\YourFileDownloader
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ICQ\ICQToolbar
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\SearchquSRTB
Key Deleted : HKLM\Software\YourFileDownloader

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]

-\\ Mozilla Firefox v30.0 (cs)

[ File : C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\prefs.js ]

Line Deleted : user_pref("CT2475029..clientLogIsEnabled", true);
Line Deleted : user_pref("CT2475029..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2475029..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2475029.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2475029.BrowserCompStateIsOpen_1000515", true);
Line Deleted : user_pref("CT2475029.BrowserCompStateIsOpen_129464711670611991", true);
Line Deleted : user_pref("CT2475029.CT2475029", "CT2475029");
Line Deleted : user_pref("CT2475029.CT2481020.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481020.alertChannelId", "874426");
Line Deleted : user_pref("CT2475029.CT2481024.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481024.alertChannelId", "874430");
Line Deleted : user_pref("CT2475029.CT2481025.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481025.alertChannelId", "874431");
Line Deleted : user_pref("CT2475029.CT2481029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481029.alertChannelId", "874435");
Line Deleted : user_pref("CT2475029.CT2481031.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481031.alertChannelId", "874437");
Line Deleted : user_pref("CT2475029.CT2481032.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481032.alertChannelId", "874438");
Line Deleted : user_pref("CT2475029.CT2481033.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481033.alertChannelId", "874439");
Line Deleted : user_pref("CT2475029.CT2481034.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481034.alertChannelId", "874440");
Line Deleted : user_pref("CT2475029.CT2481035.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481035.alertChannelId", "874441");
Line Deleted : user_pref("CT2475029.CT2481037.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CT2481037.alertChannelId", "874443");
Line Deleted : user_pref("CT2475029.CommunitiesChangesLastCheckTime", "Sat Aug 13 2011 13:07:53 GMT+0200");
Line Deleted : user_pref("CT2475029.CommunitiesChangesLastUrl", "hxxp://grouping.services.conduit.com/GroupingRequest.ctp?type=ToolbarsInfo&ctids=CT2481020,CT2481024,CT2481025,CT2481029,CT2481031,CT2481032,CT2481033[...]
Line Deleted : user_pref("CT2475029.CommunityChanged", true);
Line Deleted : user_pref("CT2475029.CurrentServerDate", "13-8-2011");
Line Deleted : user_pref("CT2475029.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2475029.DialogsGetterLastCheckTime", "Sat Aug 13 2011 13:07:39 GMT+0200");
Line Deleted : user_pref("CT2475029.DownloadDomainsCheckInterval", "168");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastCheckTime", "Sat Aug 13 2011 13:07:53 GMT+0200");
Line Deleted : user_pref("CT2475029.DownloadDomainsListLastServerUpdateTime", "1201069983");
Line Deleted : user_pref("CT2475029.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2475029.EMailNotifierPollDate", "Sat Aug 13 2011 13:07:53 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedLastCount129133095456874337", 160);
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029379", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029381", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129132307482029382", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686870", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129133095459686871", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687146", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687147", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedPollDate129137437659687148", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029379", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029381", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129132307482029382", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686870", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129133095459686871", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687146", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687147", 40);
Line Deleted : user_pref("CT2475029.FeedTTL129137437659687148", 40);
Line Deleted : user_pref("CT2475029.FirstServerDate", "13-8-2011");
Line Deleted : user_pref("CT2475029.FirstTime", true);
Line Deleted : user_pref("CT2475029.FirstTimeFF3", true);
Line Deleted : user_pref("CT2475029.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2475029.GroupingLastCheckTime", "Sat Aug 13 2011 13:07:38 GMT+0200");
Line Deleted : user_pref("CT2475029.GroupingLastErrorCode", "");
Line Deleted : user_pref("CT2475029.GroupingLastResponse", true);
Line Deleted : user_pref("CT2475029.GroupingLastServerUpdateTime", "129566026011300000");
Line Deleted : user_pref("CT2475029.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2475029.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2475029.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2475029.HomePageProtectorEnabled", false);
Line Deleted : user_pref("CT2475029.Initialize", true);
Line Deleted : user_pref("CT2475029.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2475029.InstallationAndCookieDataSentCount", 1);
Line Deleted : user_pref("CT2475029.InstallationType", "Unknown");
Line Deleted : user_pref("CT2475029.InstalledDate", "Sat Aug 13 2011 13:07:41 GMT+0200");
Line Deleted : user_pref("CT2475029.InvalidateCache", false);
Line Deleted : user_pref("CT2475029.IsGrouping", true);
Line Deleted : user_pref("CT2475029.IsInitSetupIni", true);
Line Deleted : user_pref("CT2475029.IsMulticommunity", true);
Line Deleted : user_pref("CT2475029.IsOpenThankYouPage", true);
Line Deleted : user_pref("CT2475029.IsOpenUninstallPage", true);
Line Deleted : user_pref("CT2475029.IsProtectorsInit", true);
Line Deleted : user_pref("CT2475029.LanguagePackLastCheckTime", "Sat Aug 13 2011 13:07:41 GMT+0200");
Line Deleted : user_pref("CT2475029.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2475029.LastLogin_3.6.0.10", "Sat Aug 13 2011 13:07:38 GMT+0200");
Line Deleted : user_pref("CT2475029.LatestVersion", "3.3.3.2");
Line Deleted : user_pref("CT2475029.Locale", "en");
Line Deleted : user_pref("CT2475029.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2475029.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2475029.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2475029.MyStuffEnabledAtInstallation", true);
Line Deleted : user_pref("CT2475029.OriginalFirstVersion", "3.6.0.10");
Line Deleted : user_pref("CT2475029.RadioIsPodcast", false);
Line Deleted : user_pref("CT2475029.RadioLastCheckTime", "Sat Aug 13 2011 13:07:41 GMT+0200");
Line Deleted : user_pref("CT2475029.RadioLastUpdateIPServer", "3");
Line Deleted : user_pref("CT2475029.RadioLastUpdateServer", "129054397178370000");
Line Deleted : user_pref("CT2475029.RadioMediaID", "13098944");
Line Deleted : user_pref("CT2475029.RadioMediaType", "Media Player");
Line Deleted : user_pref("CT2475029.RadioMenuSelectedID", "EBRadioMenu_CT247502913098944");
Line Deleted : user_pref("CT2475029.RadioShrinkedFromSetup", false);
Line Deleted : user_pref("CT2475029.RadioStationName", "Mellesleg%20-%20Rapp");
Line Deleted : user_pref("CT2475029.RadioStationURL", "hxxp://195.228.254.168:8060/");
Line Deleted : user_pref("CT2475029.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2475029.SavedHomepage", "hxxp://www.seznam.cz/");
Line Deleted : user_pref("CT2475029.SearchEngineBeforeUnload", "MyAshampoo Customized Web Search");
Line Deleted : user_pref("CT2475029.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2475029.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=");
Line Deleted : user_pref("CT2475029.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2475029.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.SearchInNewTabLastCheckTime", "Sat Aug 13 2011 13:07:40 GMT+0200");
Line Deleted : user_pref("CT2475029.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2475029.SearchProtectorEnabled", true);
Line Deleted : user_pref("CT2475029.SearchProtectorToolbarDisabled", false);
Line Deleted : user_pref("CT2475029.ServiceMapLastCheckTime", "Sat Aug 13 2011 13:07:34 GMT+0200");
Line Deleted : user_pref("CT2475029.SettingsLastCheckTime", "Sat Aug 13 2011 13:07:34 GMT+0200");
Line Deleted : user_pref("CT2475029.SettingsLastUpdate", "1312887586");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastCheck", "Sat Aug 13 2011 13:07:34 GMT+0200");
Line Deleted : user_pref("CT2475029.ThirdPartyComponentsLastUpdate", "1246786978");
Line Deleted : user_pref("CT2475029.ToolbarShrinkedFromSetup", false);
Line Deleted : user_pref("CT2475029.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2475029");
Line Deleted : user_pref("CT2475029.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Line Deleted : user_pref("CT2475029.UserID", "UN95516534760253366");
Line Deleted : user_pref("CT2475029.ValidationData_Toolbar", 2);
Line Deleted : user_pref("CT2475029.WeatherNetwork", "");
Line Deleted : user_pref("CT2475029.WeatherPollDate", "Sat Aug 13 2011 13:07:54 GMT+0200");
Line Deleted : user_pref("CT2475029.WeatherUnit", "C");
Line Deleted : user_pref("CT2475029.alertChannelId", "868510");
Line Deleted : user_pref("CT2475029.components.1000034", true);
Line Deleted : user_pref("CT2475029.components.1000234", true);
Line Deleted : user_pref("CT2475029.components.1000515", true);
Line Deleted : user_pref("CT2475029.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Line Deleted : user_pref("CT2475029.globalFirstTimeInfoLastCheckTime", "Sat Aug 13 2011 13:07:38 GMT+0200");
Line Deleted : user_pref("CT2475029.homepageProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2475029.initDone", true);
Line Deleted : user_pref("CT2475029.isAppTrackingManagerOn", true);
Line Deleted : user_pref("CT2475029.isFirstRadioInstallation", false);
Line Deleted : user_pref("CT2475029.myStuffEnabled", true);
Line Deleted : user_pref("CT2475029.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2475029.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2475029.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2475029.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2475029.searchProtectorDialogDelayInSec", 10);
Line Deleted : user_pref("CT2475029.searchProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2475029.testingCtid", "");
Line Deleted : user_pref("CT2475029.toolbarAppMetaDataLastCheckTime", "Sat Aug 13 2011 13:07:38 GMT+0200");
Line Deleted : user_pref("CT2475029.toolbarContextMenuLastCheckTime", "Sat Aug 13 2011 13:07:41 GMT+0200");
Line Deleted : user_pref("CT2475029.usagesFlag", 2);
Line Deleted : user_pref("CT2504091..clientLogIsEnabled", true);
Line Deleted : user_pref("CT2504091..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
Line Deleted : user_pref("CT2504091..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
Line Deleted : user_pref("CT2504091.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Line Deleted : user_pref("CT2504091.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Line Deleted : user_pref("CT2504091.BrowserCompStateIsOpen_129566938558801595", true);
Line Deleted : user_pref("CT2504091.BrowserCompStateIsOpen_129707804829376918", true);
Line Deleted : user_pref("CT2504091.CTID", "ct2504091");
Line Deleted : user_pref("CT2504091.CurrentServerDate", "9-10-2012");
Line Deleted : user_pref("CT2504091.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2504091.DialogsGetterLastCheckTime", "Sat Oct 06 2012 16:22:17 GMT+0200");
Line Deleted : user_pref("CT2504091.DownloadReferralCookieData", "");
Line Deleted : user_pref("CT2504091.EMailNotifierPollDate", "Mon Jul 04 2011 09:12:54 GMT+0200");
Line Deleted : user_pref("CT2504091.FeedPollDate128891351169457140", "Wed Jul 18 2012 13:51:47 GMT+0200");
Line Deleted : user_pref("CT2504091.FeedPollDate129079840422964131", "Wed Jul 18 2012 13:29:27 GMT+0200");
Line Deleted : user_pref("CT2504091.FeedTTL128891351169457140", 40);
Line Deleted : user_pref("CT2504091.FirstServerDate", "4-7-2011");
Line Deleted : user_pref("CT2504091.FirstTime", true);
Line Deleted : user_pref("CT2504091.FirstTimeFF3", true);
Line Deleted : user_pref("CT2504091.FixPageNotFoundErrors", true);
Line Deleted : user_pref("CT2504091.GroupingServerCheckInterval", 1440);
Line Deleted : user_pref("CT2504091.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Line Deleted : user_pref("CT2504091.HasUserGlobalKeys", true);
Line Deleted : user_pref("CT2504091.Initialize", true);
Line Deleted : user_pref("CT2504091.InitializeCommonPrefs", true);
Line Deleted : user_pref("CT2504091.InstallationAndCookieDataSentCount", 3);
Line Deleted : user_pref("CT2504091.InstallationType", "ConduitIntegration");
Line Deleted : user_pref("CT2504091.InstalledDate", "Mon Jul 04 2011 07:06:17 GMT+0200");
Line Deleted : user_pref("CT2504091.IsAlertDBUpdated", true);
Line Deleted : user_pref("CT2504091.IsGrouping", false);
Line Deleted : user_pref("CT2504091.IsInitSetupIni", true);
Line Deleted : user_pref("CT2504091.IsMulticommunity", false);
Line Deleted : user_pref("CT2504091.IsOpenThankYouPage", false);
Line Deleted : user_pref("CT2504091.IsOpenUninstallPage", false);
Line Deleted : user_pref("CT2504091.LanguagePackLastCheckTime", "Mon Jul 04 2011 07:06:21 GMT+0200");
Line Deleted : user_pref("CT2504091.LanguagePackReloadIntervalMM", 1440);
Line Deleted : user_pref("CT2504091.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
Line Deleted : user_pref("CT2504091.LastLogin_3.12.2.3", "Mon Jun 04 2012 14:55:30 GMT+0200");
Line Deleted : user_pref("CT2504091.LastLogin_3.13.0.6", "Mon Jul 16 2012 14:56:27 GMT+0200");
Line Deleted : user_pref("CT2504091.LastLogin_3.14.1.0", "Tue Aug 21 2012 11:38:42 GMT+0200");
Line Deleted : user_pref("CT2504091.LastLogin_3.15.1.0", "Tue Oct 09 2012 10:12:51 GMT+0200");
Line Deleted : user_pref("CT2504091.LastLogin_3.5.0.12", "Wed Jul 13 2011 13:02:06 GMT+0200");
Line Deleted : user_pref("CT2504091.LatestVersion", "3.15.1.0");
Line Deleted : user_pref("CT2504091.Locale", "en-us");
Line Deleted : user_pref("CT2504091.MCDetectTooltipHeight", "83");
Line Deleted : user_pref("CT2504091.MCDetectTooltipShow", false);
Line Deleted : user_pref("CT2504091.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Line Deleted : user_pref("CT2504091.MCDetectTooltipWidth", "295");
Line Deleted : user_pref("CT2504091.MyStuffEnabledAtInstallation", true);
Line Deleted : user_pref("CT2504091.OriginalFirstVersion", "3.5.0.12");
Line Deleted : user_pref("CT2504091.SHRINK_TOOLBAR", 1);
Line Deleted : user_pref("CT2504091.SavedHomepage", "hxxp://www.seznam.cz");
Line Deleted : user_pref("CT2504091.SearchFromAddressBarIsInit", true);
Line Deleted : user_pref("CT2504091.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q=");
Line Deleted : user_pref("CT2504091.SearchInNewTabEnabled", true);
Line Deleted : user_pref("CT2504091.SearchInNewTabIntervalMM", 1440);
Line Deleted : user_pref("CT2504091.SearchInNewTabLastCheckTime", "Mon Jul 04 2011 07:06:18 GMT+0200");
Line Deleted : user_pref("CT2504091.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2504091.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID");
Line Deleted : user_pref("CT2504091.ServiceMapLastCheckTime", "Tue Oct 09 2012 11:16:57 GMT+0200");
Line Deleted : user_pref("CT2504091.SettingsLastCheckTime", "Mon Jul 04 2011 07:06:15 GMT+0200");
Line Deleted : user_pref("CT2504091.SettingsLastUpdate", "1306530423");
Line Deleted : user_pref("CT2504091.ThirdPartyComponentsInterval", 504);
Line Deleted : user_pref("CT2504091.ThirdPartyComponentsLastCheck", "Mon Jul 04 2011 07:06:14 GMT+0200");
Line Deleted : user_pref("CT2504091.ThirdPartyComponentsLastUpdate", "1246786978");
Line Deleted : user_pref("CT2504091.ToolbarShrinkedFromSetup", false);
Line Deleted : user_pref("CT2504091.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2504091");
Line Deleted : user_pref("CT2504091.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCity[...]
Line Deleted : user_pref("CT2504091.UserID", "UN73257703947054650");
Line Deleted : user_pref("CT2504091.ValidationData_Toolbar", 1);
Line Deleted : user_pref("CT2504091.alertChannelId", "897164");
Line Deleted : user_pref("CT2504091.approveUntrustedApps", false);
Line Deleted : user_pref("CT2504091.backendstorage.cbcountry_001", "435A");
Line Deleted : user_pref("CT2504091.backendstorage.cbfirsttime", "576564204A756C20313820323031322031333A32393A333020474D542B30323030");
Line Deleted : user_pref("CT2504091.backendstorage.shoppingapp.gk.exipres", "4D6F6E204A756C20323320323031322031333A32393A323820474D542B30323030");
Line Deleted : user_pref("CT2504091.backendstorage.shoppingapp.gk.geolocation", "637A6563682072657075626C6963");
Line Deleted : user_pref("CT2504091.backendstorage.url_history0001", "687474703A2F2F7777772E676F6F676C652E637A2F75726C3F73613D74267263743D6A26713D6D6F7A696C6C6125323066697265666F7826736F757263653D7765622663643D31267[...]
Line Deleted : user_pref("CT2504091.components.1000034", false);
Line Deleted : user_pref("CT2504091.ct2504091.AppTrackingLastCheckTime", "Wed Jul 13 2011 13:02:16 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.DialogsAlignMode", "LTR");
Line Deleted : user_pref("CT2504091.ct2504091.FeedLastCount129079840422964131", 10);
Line Deleted : user_pref("CT2504091.ct2504091.LanguagePackLastCheckTime", "Tue Oct 09 2012 11:29:02 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.Locale", "en-us");
Line Deleted : user_pref("CT2504091.ct2504091.SearchInNewTabLastCheckTime", "Tue Oct 09 2012 12:18:50 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.SettingsLastCheckTime", "Tue Oct 09 2012 10:12:45 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.SettingsLastUpdate", "1348763566");
Line Deleted : user_pref("CT2504091.ct2504091.ThirdPartyComponentsLastCheck", "Wed Jul 18 2012 13:51:47 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.ThirdPartyComponentsLastUpdate", "1331805997");
Line Deleted : user_pref("CT2504091.ct2504091.globalFirstTimeInfoLastCheckTime", "Wed Jul 18 2012 13:51:48 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.toolbarAppMetaDataLastCheckTime", "Tue Oct 09 2012 12:19:00 GMT+0200");
Line Deleted : user_pref("CT2504091.ct2504091.toolbarContextMenuLastCheckTime", "Wed Jul 18 2012 13:51:48 GMT+0200");
Line Deleted : user_pref("CT2504091.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"hxxp://appdown[...]
Line Deleted : user_pref("CT2504091.globalFirstTimeInfoLastCheckTime", "Mon Jul 04 2011 07:06:17 GMT+0200");
Line Deleted : user_pref("CT2504091.homepageProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2504091.initDone", true);
Line Deleted : user_pref("CT2504091.isAppTrackingManagerOn", true);
Line Deleted : user_pref("CT2504091.myStuffEnabled", true);
Line Deleted : user_pref("CT2504091.myStuffPublihserMinWidth", 400);
Line Deleted : user_pref("CT2504091.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
Line Deleted : user_pref("CT2504091.myStuffServiceIntervalMM", 1440);
Line Deleted : user_pref("CT2504091.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
Line Deleted : user_pref("CT2504091.oldAppsList", "129079840421557838,129079840422026594,111,129079849636241789,129079840422182852,129079840422339107,129079840422964131,1000034,129707804829376918,1000080,1000082,100[...]
Line Deleted : user_pref("CT2504091.revertSettingsEnabled", true);
Line Deleted : user_pref("CT2504091.searchProtectorDialogDelayInSec", 10);
Line Deleted : user_pref("CT2504091.searchProtectorEnableByLogin", true);
Line Deleted : user_pref("CT2504091.testingCtid", "");
Line Deleted : user_pref("CT2504091.toolbarAppMetaDataLastCheckTime", "Mon Jul 04 2011 07:06:16 GMT+0200");
Line Deleted : user_pref("CT2504091.toolbarContextMenuLastCheckTime", "Mon Jul 04 2011 07:06:22 GMT+0200");
Line Deleted : user_pref("CT2504091.usagesFlag", 2);
Line Deleted : user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2504091&SearchSource=13,hxxp://search.conduit.com/?ctid=CT2475029&SearchSource=13");
Line Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Web Search,MyAshampoo Customized Web Search");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/ct2504091/CT2504091", "\"ee236497b0b415fcd36e4bdcc345188c2\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/CZ", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2475029", "\"1308483850\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2504091", "\"0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=ct2504091", "\"1326306883\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en", "wVmmvqqOMqrv5xct1cJIHg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en-us", "G9mW7heT/8xIX1frcduu0A==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en", "0uSPYx+Kl2jpu8sJZMeHjw==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en-us", "mfQ70fvlD2zuBxSBj8rQqA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en", "Dclc8oo4TTv7+mAkSlUSWg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en-us", "k9un27OkAvkwB2ZmvXxTnA==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en", "K4Vqu91uAzWURlxJRdXJOg==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en-us", "4BgM4MhF/sOgPsDNmIs3Yw==");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"8076e3ce381dcd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0e0a4327275cd1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.0.12", "\"807dc126dd28cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.0.10", "\"8028f138140cc1:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2475029", "\"634485749189530000\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2504091", "\"f1c77625c0e9bd1c80a2fd6901845fa9\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2475029&octid=CT2475029", "\"1312887586\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2504091/CT2504091", "\"1306530423\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/ct2504091/CT2504091", "\"1306530423\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equalizer_dead.gif", "\"0678fe477ac91:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimize.gif", "\"046c7ab477ac91:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gif", "\"0484de117c4c91:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gif", "\"0e7a152347ac91:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif", "\"087c778347ac91:0\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"f6726278d87c7067bebc10b6654cab6b\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"634485059431430000\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en-us", "\"794b80d8b2081407f144020560a01a33\"");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/1344951.xml", "\"f3aaeb43518fe75169bb3cc881886055\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/16887175.xml", "\"ce03af5c899ba69d138bf3a5387d95a9\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/17151925.xml", "\"bfff113004d25aa7c6c512af53cd4434\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20536157.xml", "\"9709b9c177b16e0853b489d1ef7c7869\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/30261067.xml", "\"a0ad3c1ea3df329a0b8230838043c7d9\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/34655603.xml", "\"1047bb90e291d082e50a262cbae536f8\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/759251.xml", "\"d49639430729b4e4d410d4a129607ad1\"-gzip");
Line Deleted : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/816653.xml", "\"28787bb03cfe3319e7a6d119299a38fc\"-gzip");
Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\marika\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\ijkzm78c.default\\conduitCommon\\modules\\3.14.1.0");
Line Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.14.1.0");
Line Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://search.seznam.cz/?sourceid=undefined&q=");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2504091,CT2475029");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2504091,CT2475029");
Line Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2504091,CT2475029");
Line Deleted : user_pref("CommunityToolbar.globalUserId", "afee7979-3d4a-49f3-a956-a706ab8241b1");
Line Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Line Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
Line Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jul 18 2012 13:29:28 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
Line Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Jul 18 2012 13:29:36 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Line Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Line Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Line Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jul 18 2012 13:29:28 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Line Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Line Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Line Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Line Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Line Deleted : user_pref("CommunityToolbar.notifications.userId", "8fc1c90f-6695-460c-8799-f3291d6629a3");
Line Deleted : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_16887175.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_17151925.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_20536157.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_30261067.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_34655603.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_759251.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Sat Aug 13 2011 13:07:43 GMT+0200");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");

-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\marika\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [36958 octets] - [25/06/2014 11:44:15]
AdwCleaner[S0].txt - [37299 octets] - [25/06/2014 11:45:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [37360 octets] ##########

Re: Vypínání a blbnutí baterky u NB

Napsal: 25 čer 2014 17:42
od Rudy
Dejte nový log RSIT.

Re: Vypínání a blbnutí baterky u NB

Napsal: 26 čer 2014 08:17
od jasnenka
Logfile of random's system information tool 1.10 (written by random/random)
Run by marika at 2014-06-26 09:16:14
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 84 GB (62%) free of 137 GB
Total RAM: 1791 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:16:24, on 26.6.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
C:\Program Files\trend micro\marika.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKCU\..\Run: [GUDelayStartup] "C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\marika\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\marika\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ashampoo HDD Control 2 Service (AHDDC2) - Unknown owner - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Cobian Backup 11 Stínová kopie - Requester (cbVSCService11) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9321 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
winlogon.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
atieclxx
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe"
C:\windows\system32\HPSIsvc.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2920
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Microsoft Security Client\msseces.exe"
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "http://www.zumailfeed.cz/click/4b2b46ec ... 220140370/"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe7_ Global\UsGthrCtrlFltPipeMssGthrPipe7 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2728.e97f9d0.1454365494 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 2728 "\\.\pipe\gecko-crash-server-pipe.2728" plugin
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe" --proxy-stub-channel=Flash4052.67A1A378.28461 --host-broker-channel=Flash4052.67A1A378.26441 --host-pid=4052 --host-npapi-version=27 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll"
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe" --channel=2652.0044F3DC.169924820 --proxy-stub-channel=Flash4052.67A1A378.28461 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll" --host-npapi-version=27 --type=renderer

"C:\windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\marika\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GlaryInitialize 5.job - C:\Program Files (x86)\Glary Utilities 5\Initialize.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/?clid=3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.206 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 13.0.0.206 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.55.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL


C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\marika\AppData\Roaming\Mozilla\Firefox\Profiles\ijkzm78c.default\searchplugins\
firmycz.xml
mapycz.xml
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-04-16 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-03-21 6270336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-04-16 211368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GUDelayStartup"=C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [2014-06-16 37152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cobian Backup 11 interface]
C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [2012-07-31 4407808]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\marika\AppData\Local\Google\Update\GoogleUpdate.exe /c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
C:\Users\marika\AppData\Roaming\ICQM\icq.exe [2013-11-07 29919576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 1271072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-06-24 1833504]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StickyPassword]
C:\Program Files (x86)\Sticky Password\stpass.exe [2014-05-23 14140728]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avas_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avss_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tpavdrw_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tpmgma_service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-06-25 11:45:18 ----A---- C:\windows\SYSWOW64\sqlite3.dll
2014-06-25 11:44:13 ----D---- C:\AdwCleaner
2014-06-25 10:47:10 ----N---- C:\bootsqm.dat
2014-06-20 21:26:53 ----D---- C:\Users\marika\AppData\Roaming\JAM Software
2014-06-20 16:01:35 ----AD---- C:\Kaspersky Rescue Disk 10.0
2014-06-20 12:17:44 ----D---- C:\Users\marika\AppData\Roaming\Ashampoo
2014-06-20 12:17:19 ----D---- C:\ProgramData\Ashampoo
2014-06-18 10:07:29 ----A---- C:\windows\system32\drivers\BootDefragDriver.sys
2014-06-11 13:26:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-06-11 11:36:43 ----A---- C:\windows\SYSWOW64\msxml6.dll
2014-06-11 11:36:43 ----A---- C:\windows\system32\msxml6.dll
2014-06-11 11:36:43 ----A---- C:\windows\system32\msxml3.dll
2014-06-11 11:36:42 ----A---- C:\windows\SYSWOW64\msxml6r.dll
2014-06-11 11:36:42 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2014-06-11 11:36:42 ----A---- C:\windows\SYSWOW64\msxml3.dll
2014-06-11 11:36:42 ----A---- C:\windows\system32\msxml6r.dll
2014-06-11 11:36:42 ----A---- C:\windows\system32\msxml3r.dll
2014-06-11 11:36:40 ----A---- C:\windows\system32\drivers\tcpip.sys
2014-06-11 11:36:39 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-11 11:36:37 ----A---- C:\windows\SYSWOW64\usp10.dll
2014-06-11 11:36:37 ----A---- C:\windows\system32\usp10.dll
2014-06-11 11:36:34 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-06-11 11:36:34 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-06-11 11:36:33 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-06-11 11:36:33 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-06-11 11:36:32 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-06-11 11:36:32 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-06-11 11:36:32 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-11 11:36:32 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-06-11 11:36:32 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 11:36:32 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-06-11 11:36:30 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-06-11 11:36:29 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-06-11 11:36:29 ----A---- C:\windows\system32\urlmon.dll
2014-06-11 11:36:28 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-06-11 11:36:28 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-06-11 11:36:28 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-06-11 11:36:27 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-06-11 11:36:27 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-06-11 11:36:27 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-06-11 11:36:27 ----A---- C:\windows\system32\msfeeds.dll
2014-06-11 11:36:27 ----A---- C:\windows\system32\ieetwcollector.exe
2014-06-11 11:36:27 ----A---- C:\windows\system32\dxtmsft.dll
2014-06-11 11:36:26 ----A---- C:\windows\system32\ie4uinit.exe
2014-06-11 11:36:25 ----A---- C:\windows\system32\iesetup.dll
2014-06-11 11:36:24 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-06-11 11:36:24 ----A---- C:\windows\system32\iertutil.dll
2014-06-11 11:36:23 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-06-11 11:36:23 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-06-11 11:36:23 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-06-11 11:36:23 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-06-11 11:36:22 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-06-11 11:36:22 ----A---- C:\windows\system32\jsproxy.dll
2014-06-11 11:36:22 ----A---- C:\windows\system32\iernonce.dll
2014-06-11 11:36:21 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-06-11 11:36:15 ----A---- C:\windows\system32\ieui.dll
2014-06-11 11:36:15 ----A---- C:\windows\system32\dxtrans.dll
2014-06-11 11:36:13 ----A---- C:\windows\system32\ieframe.dll
2014-06-11 11:36:12 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-06-11 11:36:12 ----A---- C:\windows\system32\mshtmled.dll
2014-06-11 11:36:12 ----A---- C:\windows\system32\ieUnatt.exe
2014-06-11 11:36:11 ----A---- C:\windows\system32\vbscript.dll
2014-06-11 11:36:11 ----A---- C:\windows\system32\jscript9diag.dll
2014-06-11 11:36:11 ----A---- C:\windows\system32\jscript9.dll
2014-06-11 11:36:11 ----A---- C:\windows\system32\ieapfltr.dll
2014-06-11 11:36:10 ----A---- C:\windows\system32\wininet.dll
2014-06-11 11:36:10 ----A---- C:\windows\system32\msrating.dll
2014-06-11 11:36:06 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-11 11:36:05 ----A---- C:\windows\system32\mshtml.dll
2014-06-11 11:35:58 ----A---- C:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 11:35:58 ----A---- C:\windows\system32\rdpcorets.dll
2014-06-11 11:34:53 ----A---- C:\windows\system32\aepdu.dll
2014-06-11 11:34:50 ----A---- C:\windows\system32\aeinv.dll
2014-06-05 06:39:13 ----A---- C:\BackupLoader.ini
2014-06-02 12:09:59 ----D---- C:\ProgramData\Lamantine

======List of files/folders modified in the last 1 month======

2014-06-26 09:16:26 ----D---- C:\windows\temp
2014-06-26 09:16:24 ----D---- C:\windows\Prefetch
2014-06-26 09:16:20 ----D---- C:\Program Files\trend micro
2014-06-26 09:15:56 ----D---- C:\Users\marika\AppData\Roaming\Skype
2014-06-26 08:00:33 ----D---- C:\windows\system32\config
2014-06-26 07:52:20 ----SHD---- C:\windows\Installer
2014-06-26 07:52:20 ----D---- C:\Config.Msi
2014-06-26 07:47:34 ----RD---- C:\Program Files (x86)
2014-06-26 07:42:04 ----D---- C:\Program Files (x86)\Glary Utilities 5
2014-06-26 07:39:29 ----D---- C:\windows\Minidump
2014-06-26 07:39:29 ----D---- C:\windows\inf
2014-06-26 07:39:29 ----D---- C:\Windows
2014-06-25 11:46:19 ----D---- C:\windows\system32\Tasks
2014-06-25 11:45:18 ----D---- C:\windows\SysWOW64
2014-06-25 10:31:06 ----SHD---- C:\System Volume Information
2014-06-25 09:57:40 ----D---- C:\windows\System32
2014-06-25 09:57:39 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-06-24 10:19:04 ----D---- C:\windows\SoftwareDistribution
2014-06-23 12:14:10 ----D---- C:\windows\system32\catroot2
2014-06-23 10:55:24 ----D---- C:\Program Files (x86)\trend micro
2014-06-21 17:58:26 ----RD---- C:\Program Files
2014-06-20 12:17:19 ----D---- C:\ProgramData
2014-06-20 12:16:12 ----D---- C:\Program Files (x86)\Ashampoo
2014-06-18 10:07:33 ----D---- C:\windows\Tasks
2014-06-18 10:07:29 ----D---- C:\windows\system32\drivers
2014-06-18 09:50:19 ----D---- C:\Users\marika\AppData\Roaming\DiskDefrag
2014-06-16 10:37:50 ----A---- C:\windows\system32\RegBootDefrag.exe
2014-06-16 10:37:42 ----A---- C:\windows\system32\BootDefrag.exe
2014-06-13 09:39:23 ----D---- C:\windows\rescache
2014-06-12 12:49:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-11 13:29:44 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2014-06-11 12:06:43 ----D---- C:\windows\debug
2014-06-11 11:54:15 ----D---- C:\windows\winsxs
2014-06-11 11:48:39 ----D---- C:\Program Files\Internet Explorer
2014-06-11 11:48:36 ----D---- C:\windows\SYSWOW64\en-US
2014-06-11 11:48:30 ----D---- C:\windows\system32\en-US
2014-06-11 11:48:27 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-11 11:48:23 ----D---- C:\windows\system32\DriverStore
2014-06-11 11:47:31 ----D---- C:\windows\system32\MRT
2014-06-11 11:44:38 ----A---- C:\windows\system32\MRT.exe
2014-06-11 11:42:32 ----D---- C:\ProgramData\Microsoft Help
2014-06-11 11:40:07 ----SD---- C:\windows\system32\CompatTel
2014-06-11 11:35:40 ----D---- C:\windows\system32\catroot
2014-06-04 09:46:01 ----D---- C:\windows\system32\LogFiles
2014-06-03 10:33:04 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-06-03 10:33:04 ----D---- C:\Program Files (x86)\Electronic Arts
2014-06-02 15:25:03 ----D---- C:\ProgramData\Origin
2014-06-02 12:10:15 ----D---- C:\Program Files (x86)\Sticky Password
2014-05-29 07:08:05 ----D---- C:\Program Files\CCleaner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 BootDefragDriver;BootDefragDriver; C:\windows\System32\drivers\BootDefragDriver.sys [2014-06-16 17600]
R0 GUBootStartup;GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [2014-05-15 20672]
R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2014-01-25 268512]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 133928]
R3 atikmdag;atikmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2009-07-30 6038016]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2009-06-24 1787168]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2013-02-25 2426672]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-06-04 216064]
R3 RTHDMIAzAudService;Service for HDMI; C:\windows\system32\drivers\RtHDMIVX.sys [2009-06-24 205472]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-11-27 295424]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 mvusbews;USB EWS Device; C:\windows\System32\Drivers\mvusbews.sys [2012-12-24 20480]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RtsUIR;Realtek IR Driver; C:\windows\system32\DRIVERS\Rts516xIR.sys []
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 smserial;smserial; C:\windows\system32\DRIVERS\SmSerl64.sys [2009-06-10 1227776]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AHDDC2;Ashampoo HDD Control 2 Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [2011-04-05 1518976]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2009-07-30 203264]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 cbVSCService11;Cobian Backup 11 Stínová kopie - Requester; C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe [2012-07-31 67584]
R2 HP LaserJet Service;HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192]
R2 HPSIService;HP SI Service; C:\windows\system32\HPSIsvc.exe [2011-05-18 126520]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 23808]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 TeamViewer9;TeamViewer 9; C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-25 5024576]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 347872]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-04 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-28 257712]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 DfSdkS;Defragmentation-Service; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [2009-08-24 544768]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-04 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-06-11 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-05-17 1255736]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: Vypínání a blbnutí baterky u NB

Napsal: 26 čer 2014 16:50
od Rudy
Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files (x86)\Skype\Toolbars
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]

:services
c2cautoupdatesvc
c2cpnrsvc
SeaPort

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.