Prosim o kontrolu, vyskakuje tabulka inet32upd.exe openCL.dl
Napsal: 03 čer 2015 20:37
Logfile of random's system information tool 1.10 (written by random/random)
Run by Pavlína at 2015-06-03 21:35:20
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 17 GB (22%) free of 77 GB
Total RAM: 766 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:30, on 3.6.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění\conhost32.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění\conhost64.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Documents and Settings\Pavlína\Data aplikací\Microsoft\Networking\inet32upd.exe
C:\Program Files\SupTab\HpUI.exe
C:\Program Files\SupTab\Loader32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pavlína\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Pavlína.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {8ba2cfef-a1bc-4964-aadc-33be1ae5a33c} - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Search Assistant BHO - {9b9dcae3-be34-424c-8d73-75e305a9e091} - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll
O2 - BHO: Toolbar BHO - {dc9051c2-8f55-479a-97a4-747980d9047f} - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbar.dll
O3 - Toolbar: WeatherBlink - {f20de5e0-2a6e-4c54-985f-1cf59551ce39} - C:\Program Files\WeatherBlink\bar\2.bin\gcbar.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [WeatherBlink AppIntegrator 32-bit] C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WeatherBlink Search Scope Monitor] "C:\PROGRA~1\WEATHE~2\bar\2.bin\gcsrchmn.exe" /m=2 /w /h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DoctorPC] C:\Program Files\Doctor PC\DoctorPC.exe true
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: conhost32.exe
O4 - Startup: conhost64.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: &Search - http://buttons.weatherblink.com/one-too ... 10406&cv=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Update Rad Rater - Unknown owner - C:\Program Files\Rad Rater\updateRadRater.exe (file missing)
O23 - Service: WeatherBlinkService - Mindspark - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbarsvc.exe
--
End of file - 8356 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\BFFOY.job - C:\Documents and Settings\Pavlna\Data aplikac\BFFOY.exe /infocmdline=k8zlvKUqD7x5PJWKGRDdjUTj/+hFoIl1B9l3I6khbTQqM/PKwrItYrHqxzgrjdfc08LfcUGRNXjp6T6jbE88uZ3DNB7BytYiisfZw5q5OouvUqvSpyUm/iyEW8b3EP5qBLIAJE5tVlFL9GzNa4V4FfN5+xdOipPt/gXISijz1cQ8Um192i8pm+WUi8icujOSjQI2HmK8erpctlZDLD0Uh8en73LlHlRUFxlMw6nU+a/b927GO/xyy4PryWcW2RP4yNjP0rabb1EIwU8Tk6id4xW/qwKR/sPuUdqav7aYwoapNU5o4lOOHGv862UuXKM197SHAAH7itWUKHkmZfwlk6JtSOfdDbOSqPG4v8QYi1CiOk7m5+majjetRaOowUdfXj/8xeDNkb7pBY+HkR6HcZxs96yUmz+GYcUr1JVMqJVgiYtH15AF27CdX5hy1A3gC6Wkd4VyGoTiu1/rps086MjC4CdGwQMa/d4oHZaiSs/2JS9dZKn04hal+Z63RsjL
C:\WINDOWS\tasks\BLIVMIF.job - C:\Documents and Settings\Pavlna\Data aplikac\BLIVMIF.exe /infocmdline=uIwUjlBLmlenfEqgce1ykGlrAW5uII954pcfiIjZEj3DhpwJQOAqYZIv180LwBQCU3GRRdNowpgqsypFcgmyu4VnX07rwZslXOZU0H8ior7m8R3EKnwQPhRU33H6olqdjoVCKIxzjlhH2RIFHge7Lqf+wGfzAkpy/nCWz77zDAR3fFlW/S4ZBxm7hj9CLzuWYQGE/Vca4sd3WA6nPFderqCm4WkARDElJu8QplaxaxYxiijpML0ZxQQhFsbIrW+sF8zxZ6ifhr6kS1ARD7DHg2gB23NNc+KnYPaX9MNRdfq1e731O4sBM3yQCA3PeLD6pCj8HTid3XTT2HyRs7iXRE/x/1aZ8/ccyRXr6EGnKX9GOYR46pWPdEOj47oKxphVPMOxBxjinbPFax/henNpeoHvnmIXAemUD5w6rOip9Gvu2xfWei5qHbo+e6xvcPcfedZWz+v24sgOt8ULLrf8qP38Vltfh7sLOXDnLAMInFzaeYX2zYAlQz+K9YUn8CLXqA5POcZgiGcz88A0D/owDv2EW28VYmjIYUpcNAfwwBd8A7nOqSIXtDw3Vqe0JeZHQr6Yp/Ves+OqMM8587Ryv2iCkwpevi6rrr9x9A4crcJfU6S+2xTNAyYBSdpWy9qW1vh9vSUNyhCrdLSjq0PfHww9PoW/hIZdMw4hjfXxM70=
C:\WINDOWS\tasks\BOAOQS.job - C:\Documents and Settings\Pavlna\Data aplikac\BOAOQS.exe /infocmdline=rJz1mXkqhv80RhnhI+djPl+t/NZxmaZUztFaGWI5f3IHPJcDs/74K5mibt4lL0du8Otpn8LOLBkIukg8S+Goyn2fy9rx4/hxwJ/11Gc/3ohBZsEVzTdSKKBIP0uOIn6FObKLnxMoLCz9/q+/mstjRT8BDqAcFLQdLd8cb1c84vUieaD8kKzEJlh87qiv0qnPpZY6D3TYP1SnexpkwsywNo2Dn0fJAgD1QyXxd28/SqGFxIjKpMc++GIYU3NeI+gZGl1oEtjNEwcO2bzVeDgfmPiIyyAUKxJbbdFaoUIjZUPrOs25R30LExZOTLqD3rqfTcwQgsmergArVKLh/ii0f1NTHH+pbJKYRmI0Z3IXE+PFkM7fBRepFuowuS6jvcR96L20KxyTs1tbGcEf9hmN52Jgtg+5KhWIzOFuYIA7wtYsg52NOPiIIZlAs6pL64yENO2y5A0sPXs6hVXE1Wy+yBVdhdkWcNSzACMkcQvscnKB9VXwLKzr1vGAyoeasb7e
C:\WINDOWS\tasks\BQHUM.job - C:\Documents and Settings\Pavlna\Data aplikac\BQHUM.exe /infocmdline=wU+9lX3YEpN+jlQPYAC+lATHhh/mp8HudSSRG0zvKrvSpxFzjdyxLP45gzvPG37gY/wwxYucbbuLfSbnhVEZw6ns4vRHWcOf9dxNCj74lpV801MXXEjYmtA4H3vZz25pxc7rMkvr711oY/M+6VuTnVCfLIJTVA2jlx2VXcn3nEMI+9dgI9+wLhgrXidvAYkBXWVR48d/7sL8l61V5gIPYd5hNwOwZroLOf+Brh9rbupqB8nae2Le19+rUeW3lM3Q/ovFNR2F0qIBeTDzYR1QU9u7T4JqNRcBWIXwTQgHjXrAmgJzvc/gG9NHuEbp3oRH80y4nt+y4V0t5j8R6eBy/RBGEAL84A7lADtPaY8zePqcc8IwXnH56sVMmDhv+gSgIGeXSJIOdD/nydKUQ7sewmbF1St6VeA11ZRg9lL+wwph9VPy63hoCsBCxiR5ouwu39fcK4rhK3Hmu93TFtC5cm1l1t8aXQS8UsmLsm/qNtY6aMuTj8wh2v7SAFMsjwi0
C:\WINDOWS\tasks\DoctorPC_Popup.job - C:\Program Files\Doctor PC\Splash.exe true
C:\WINDOWS\tasks\FKVHSDS.job - C:\Documents and Settings\Pavlna\Data aplikac\FKVHSDS.exe /infocmdline=JTjCyRPIEg5fz7Idk1TBs+mjMnu0NF7lV2ezVlDB8ag+rsVVsB7saGjFKynxzGi3bekrs4jV3XOUlK0XRzumswcjc3ZoSKjwbYJQjIO3PX/MdNfpoX39evATfqlJ0dlFMDic/5nDk1KIR6QSVYR8Gby77G6t3IH6OOoqMKoVN1lxw+RnTX9dXhtGiX5GZxvdy2MiPJnj7bMsa/viwPXqaXN3eq2qewsmhxng+XWbYsPYgJQphaUAHTi7lxXHUx5o1u1OP/ImgHi6lRY+Mo5DA7xiuIwMu9DpOlLo9ltXJf42ccKjrwRDPhSUSYw6oFJ+ULqphxaHMfHPHA+E3Pwj2aM5+qy9XDVatuKicAqej7J+sw3ELpL4d9hRLtCuKbeZ7a74VrKTss/5AACzt8Bi3QLo3q2zcvJUvArDZAVi+cj0AtkgWx7LM+o5vQk4sIhsT5xMDn+vTvccRqEBhZL6GsB8J94iR2W5jXZUZtnt9o97Yr7t8puZJ6kuPKA5V6VE
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\IPZCVMDS.job - C:\Documents and Settings\Pavlna\Data aplikac\IPZCVMDS.exe /infocmdline=iIVV5AqM51PFkjzeiY/ityPS15reZAKaRX4VjQiA2r+Vif0xE/tek3jfJPuMJYwkPwVUmeWJ6/UZyHiiLVzc9FKinciESqWsIAjYM2CjZ6FcC9ixuCoCFVD3hd1coXM5s1oyjRUDair/wqgxdEIRDQ73BnQiThZVwpEjcdHuJNI7j+aWoPtZJ2JURdvMThIJgryyPNJbyI3C917GjZ0am0p4gdykNxsJfiUT4XGEEulgI/ga8VDMqoAPvC4tmchoxtF8qqJvnv1YeHq222GgYdgATAA5Ly7XYi2evPBnuqRn9dMwPc2LNzLwGPf5UdT7nOdYKiEoJeqQhqm4odlqM65K6jqlSWHJchqLLDrk0cr/jMz1gFUoSbB/k7s3ju0RvbEotQiynC+73nK/oDLYfude9o58fybVxiJeezye1/ZqRA/bGM4kCp5ZySrk235C7FDRpHUWnCho7vOH2lJzZD8TmFMYjXWpjBRTm+OVRTGDvWKyrFJKwOQh3bRTX2ZusZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\SDT.job - C:\Documents and Settings\Pavlna\Data aplikac\SDT.exe /infocmdline=cFarxy0zu1jgXAT1ge3JVkPuHnC/lepFjxWtoAu5PjVhy9cDLj2Q5pBkjdh7UK41qpCuqYvLadQEIhI40U1Qcee/lWt29EuTjaMugXduffN69oeMkYIojaGc/KybtpxrK5CQ4Kmi/E3mfuxDq2otESdjldMrk2l4/IyZ2uJ0SstVh2lIihcq35JlV73AhMHm+LkROn9j43aoBVaQtBK5Qptq0m5RVEi6m37sxYCr8axfm+u4T09P6VsPa8USG4cL4gnZsp4qy0hVK28rfhCFqvmu0McwNd/l60XzhaCAYouOGuqS7tP7UFNU4mR+FgVn7PFi5QbzSs+MclB2T3863U25eUdt7/vKWBQh3sU1qhJ2EQrfJD2SJ096RxW42kJVKxbX/W09EHDw/LXCaAljqd4VVncwfGbv6TBHrZvMWiXcmWx6HDKw1DEuGjvMUC3eZ3n+UbVMnUO4oHQmibZUeITtzVobF7i++JPX97j3o+GRh/hrr1VSTKwirPdbKFKv
C:\WINDOWS\tasks\YTVJIN.job - C:\Documents and Settings\Pavlna\Data aplikac\YTVJIN.exe /infocmdline=iG4oBdMdSoyfkqRdbbpUE6tmY/9w4IYb2lxgxq856qny9TqMwm0J9G5xanCJaWH6O9xVL6rgJhkn9Au8AXXqbJXfcTRLuU8TO/+OeO6rmyGAicOFe51G9C1EzsE8oVBPJ68v4O4HuTuHyu+HOC5o+dbNjBGb4nN1Z/OHjxW4hWfGMUMc4BM4FKnb4SZ1pDCs7DI/7kPkwa9qbxJvt+glQIy+dLeD46M8CRZcx/rS4tpD9sbXsrZFeCgw8Mz6MD4yb+Dcnk+qfBe71/pylqMn2E4g2fGQxVWYBb3yzgZD3x0MFhacquPX3yfG9iHOO/4pv2En9lkXEEd7mEFuu+wFoTGOwZY+XHpgd0G3PiufVcJuWWLuC0C8J4glXoMuVbQO0o0nrCXYZ1fMil1ryZ2sxBXg54Ox4Td/4eRzuTLve9hNoynnuyxdwCn4N8p97Db+OqujGzjz030pdppG6dfu6l4Ys1j0tDf6cABs3hMcPOfj4JwbkFn0JlCBwC5a+czY
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default
prefs.js - "Keyword.Enabled" - "true"
prefs.js - "browser.search.useDBForOrder" - false
prefs.js - "browser.startup.homepage" - "http://home.tb.ask.com/index.jhtml?ptb= ... tAodOSEATQ"
prefs.js - "keyword.URL" - "http://search.tb.ask.com/search/GGmain. ... searchfor="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1214154.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll
C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default\extensions\
89ffxtbr@SafePCRepair_89.com
9pffxtbr@OnlineMapFinder_9p.com
staged
veggy@veggyAddon.com
{58e3c1c9-2dc1-4762-bd45-1df9da9d0820}
{6726b74d-ed76-7f21-e782-28d509370ade}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default\searchplugins\
ask-search.xml
ask-web-search.xml
myplaycity.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files\SupTab\SupTab.dll [2014-12-03 515464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-17 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9b9dcae3-be34-424c-8d73-75e305a9e091}]
Search Assistant BHO - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll [2015-05-21 144968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-17 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dc9051c2-8f55-479a-97a4-747980d9047f}]
Toolbar BHO - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbar.dll [2015-05-21 1037896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{f20de5e0-2a6e-4c54-985f-1cf59551ce39} - WeatherBlink - C:\Program Files\WeatherBlink\bar\2.bin\gcbar.dll [2015-05-21 1037896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-19 1183656]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-19 1958800]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-17 87584]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"WeatherBlink AppIntegrator 32-bit"=C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe [2015-05-21 225864]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-04-30 334896]
"WeatherBlink Search Scope Monitor"=C:\PROGRA~1\WEATHE~2\bar\2.bin\gcsrchmn.exe /m=2 /w /h []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"cz.seznam.software.autoupdate"=C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"DoctorPC"=C:\Program Files\Doctor PC\DoctorPC.exe true []
"Steam"=C:\Program Files\Steam\steam.exe [2015-06-02 2892992]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění
conhost32.exe
conhost64.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-15 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Counter-Strike 1.6 Standalone\launcher.exe"="C:\Program Files\Counter-Strike 1.6 Standalone\launcher.exe:*:Enabled:Creted by Martin.cz"
"C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe"="C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe:*:Enabled:UDK"
"C:\WarThunder\launcher.exe"="C:\WarThunder\launcher.exe:*:Enabled:War Thunder launcher"
"C:\WarThunder\bpreport.exe"="C:\WarThunder\bpreport.exe:*:Enabled:War Thunder Crash Reporter"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Steam\bin\steamwebhelper.exe"="C:\Program Files\Steam\bin\steamwebhelper.exe:*:Enabled:Steam Web Helper"
"D:\team fortess2\steamapps\common\Team Fortress 2\hl2.exe"="D:\team fortess2\steamapps\common\Team Fortress 2\hl2.exe:*:Enabled:Team Fortress 2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"vidc.VP62"=vp6vfw.dll
======List of files/folders created in the last 1 month======
2015-06-03 21:35:21 ----D---- C:\Program Files\trend micro
2015-06-03 21:35:20 ----D---- C:\rsit
2015-06-03 20:36:58 ----A---- C:\Boot.bak
2015-06-03 20:36:52 ----RASHD---- C:\cmdcons
2015-06-03 20:34:30 ----A---- C:\WINDOWS\zip.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWSC.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWREG.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\sed.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\PEV.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\NIRCMD.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\MBR.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\grep.exe
2015-06-03 20:34:24 ----SD---- C:\ComboFix
2015-06-03 20:34:12 ----D---- C:\Qoobox
2015-06-03 20:33:54 ----D---- C:\WINDOWS\erdnt
2015-05-23 14:17:52 ----HD---- C:\WINDOWS\PIF
2015-05-17 10:33:37 ----D---- C:\Documents and Settings\Pavlína\Data aplikací\.minecraft
2015-05-17 10:32:19 ----D---- C:\Program Files\Common Files\Java
2015-05-17 10:27:34 ----D---- C:\Program Files\Java
2015-05-17 09:30:51 ----D---- C:\Program Files\McAfee Security Scan
2015-05-16 21:18:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan
2015-05-10 13:53:41 ----D---- C:\Program Files\NVIDIA Corporation
2015-05-10 13:52:48 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
======List of files/folders modified in the last 1 month======
2015-06-03 21:35:21 ----RD---- C:\Program Files
2015-06-03 21:34:26 ----D---- C:\Program Files\Steam
2015-06-03 21:33:32 ----D---- C:\WINDOWS\Temp
2015-06-03 21:33:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-06-03 21:22:44 ----D---- C:\WINDOWS\system32\CatRoot2
2015-06-03 20:36:58 ----RASH---- C:\boot.ini
2015-06-03 20:34:30 ----D---- C:\WINDOWS
2015-06-03 20:34:25 ----D---- C:\WINDOWS\Prefetch
2015-06-03 20:34:13 ----D---- C:\WINDOWS\system32\drivers
2015-06-03 20:28:32 ----D---- C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz
2015-05-24 11:32:27 ----D---- C:\Program Files\The KMPlayer
2015-05-22 18:01:34 ----SD---- C:\Documents and Settings\Pavlína\Data aplikací\Microsoft
2015-05-17 10:32:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Oracle
2015-05-17 10:32:23 ----SHD---- C:\WINDOWS\Installer
2015-05-17 10:32:19 ----D---- C:\Program Files\Common Files
2015-05-17 10:31:56 ----D---- C:\WINDOWS\system32
2015-05-17 10:30:26 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-05-16 21:18:39 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-05-15 20:36:15 ----SD---- C:\WINDOWS\Tasks
2015-05-13 21:25:39 ----D---- C:\WINDOWS\system32\MRT
2015-05-13 21:19:48 ----A---- C:\WINDOWS\system32\MRT.exe
2015-05-10 13:54:49 ----D---- C:\WINDOWS\system32\DirectX
2015-05-10 13:54:48 ----HD---- C:\WINDOWS\inf
2015-05-10 13:54:26 ----RSD---- C:\WINDOWS\assembly
2015-05-10 13:52:46 ----D---- C:\WINDOWS\WinSxS
2015-05-10 09:18:26 ----HD---- C:\Program Files\InstallShield Installation Information
2015-05-10 09:18:18 ----D---- C:\Program Files\Activision
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\System32\DRIVERS\snapman.sys [2014-08-13 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\System32\DRIVERS\timntr.sys [2014-08-13 395744]
R1 {6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt;{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt; C:\WINDOWS\system32\drivers\{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt.sys [2014-12-03 55824]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [2014-08-13 39264]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-12-15 1463296]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2008-07-25 176640]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 cpuz134;cpuz134; \??\C:\DOCUME~1\PAVLNA~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-17 230944]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2005-12-15 405504]
R2 IePluginServices;IePlugin Services; C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe [2014-12-03 715656]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-12-14 520192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S2 Update Rad Rater;Update Rad Rater; C:\Program Files\Rad Rater\updateRadRater.exe []
S2 WeatherBlinkService;WeatherBlinkService; C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbarsvc.exe [2015-05-21 90696]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-16 268464]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 235696]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-11 114800]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Pavlína at 2015-06-03 21:35:20
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 17 GB (22%) free of 77 GB
Total RAM: 766 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:35:30, on 3.6.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění\conhost32.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění\conhost64.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Documents and Settings\Pavlína\Data aplikací\Microsoft\Networking\inet32upd.exe
C:\Program Files\SupTab\HpUI.exe
C:\Program Files\SupTab\Loader32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pavlína\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Pavlína.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XX4MT1QD3Y
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {8ba2cfef-a1bc-4964-aadc-33be1ae5a33c} - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Search Assistant BHO - {9b9dcae3-be34-424c-8d73-75e305a9e091} - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll
O2 - BHO: Toolbar BHO - {dc9051c2-8f55-479a-97a4-747980d9047f} - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbar.dll
O3 - Toolbar: WeatherBlink - {f20de5e0-2a6e-4c54-985f-1cf59551ce39} - C:\Program Files\WeatherBlink\bar\2.bin\gcbar.dll
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [WeatherBlink AppIntegrator 32-bit] C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WeatherBlink Search Scope Monitor] "C:\PROGRA~1\WEATHE~2\bar\2.bin\gcsrchmn.exe" /m=2 /w /h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DoctorPC] C:\Program Files\Doctor PC\DoctorPC.exe true
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: conhost32.exe
O4 - Startup: conhost64.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
O8 - Extra context menu item: &Search - http://buttons.weatherblink.com/one-too ... 10406&cv=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Update Rad Rater - Unknown owner - C:\Program Files\Rad Rater\updateRadRater.exe (file missing)
O23 - Service: WeatherBlinkService - Mindspark - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbarsvc.exe
--
End of file - 8356 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\BFFOY.job - C:\Documents and Settings\Pavlna\Data aplikac\BFFOY.exe /infocmdline=k8zlvKUqD7x5PJWKGRDdjUTj/+hFoIl1B9l3I6khbTQqM/PKwrItYrHqxzgrjdfc08LfcUGRNXjp6T6jbE88uZ3DNB7BytYiisfZw5q5OouvUqvSpyUm/iyEW8b3EP5qBLIAJE5tVlFL9GzNa4V4FfN5+xdOipPt/gXISijz1cQ8Um192i8pm+WUi8icujOSjQI2HmK8erpctlZDLD0Uh8en73LlHlRUFxlMw6nU+a/b927GO/xyy4PryWcW2RP4yNjP0rabb1EIwU8Tk6id4xW/qwKR/sPuUdqav7aYwoapNU5o4lOOHGv862UuXKM197SHAAH7itWUKHkmZfwlk6JtSOfdDbOSqPG4v8QYi1CiOk7m5+majjetRaOowUdfXj/8xeDNkb7pBY+HkR6HcZxs96yUmz+GYcUr1JVMqJVgiYtH15AF27CdX5hy1A3gC6Wkd4VyGoTiu1/rps086MjC4CdGwQMa/d4oHZaiSs/2JS9dZKn04hal+Z63RsjL
C:\WINDOWS\tasks\BLIVMIF.job - C:\Documents and Settings\Pavlna\Data aplikac\BLIVMIF.exe /infocmdline=uIwUjlBLmlenfEqgce1ykGlrAW5uII954pcfiIjZEj3DhpwJQOAqYZIv180LwBQCU3GRRdNowpgqsypFcgmyu4VnX07rwZslXOZU0H8ior7m8R3EKnwQPhRU33H6olqdjoVCKIxzjlhH2RIFHge7Lqf+wGfzAkpy/nCWz77zDAR3fFlW/S4ZBxm7hj9CLzuWYQGE/Vca4sd3WA6nPFderqCm4WkARDElJu8QplaxaxYxiijpML0ZxQQhFsbIrW+sF8zxZ6ifhr6kS1ARD7DHg2gB23NNc+KnYPaX9MNRdfq1e731O4sBM3yQCA3PeLD6pCj8HTid3XTT2HyRs7iXRE/x/1aZ8/ccyRXr6EGnKX9GOYR46pWPdEOj47oKxphVPMOxBxjinbPFax/henNpeoHvnmIXAemUD5w6rOip9Gvu2xfWei5qHbo+e6xvcPcfedZWz+v24sgOt8ULLrf8qP38Vltfh7sLOXDnLAMInFzaeYX2zYAlQz+K9YUn8CLXqA5POcZgiGcz88A0D/owDv2EW28VYmjIYUpcNAfwwBd8A7nOqSIXtDw3Vqe0JeZHQr6Yp/Ves+OqMM8587Ryv2iCkwpevi6rrr9x9A4crcJfU6S+2xTNAyYBSdpWy9qW1vh9vSUNyhCrdLSjq0PfHww9PoW/hIZdMw4hjfXxM70=
C:\WINDOWS\tasks\BOAOQS.job - C:\Documents and Settings\Pavlna\Data aplikac\BOAOQS.exe /infocmdline=rJz1mXkqhv80RhnhI+djPl+t/NZxmaZUztFaGWI5f3IHPJcDs/74K5mibt4lL0du8Otpn8LOLBkIukg8S+Goyn2fy9rx4/hxwJ/11Gc/3ohBZsEVzTdSKKBIP0uOIn6FObKLnxMoLCz9/q+/mstjRT8BDqAcFLQdLd8cb1c84vUieaD8kKzEJlh87qiv0qnPpZY6D3TYP1SnexpkwsywNo2Dn0fJAgD1QyXxd28/SqGFxIjKpMc++GIYU3NeI+gZGl1oEtjNEwcO2bzVeDgfmPiIyyAUKxJbbdFaoUIjZUPrOs25R30LExZOTLqD3rqfTcwQgsmergArVKLh/ii0f1NTHH+pbJKYRmI0Z3IXE+PFkM7fBRepFuowuS6jvcR96L20KxyTs1tbGcEf9hmN52Jgtg+5KhWIzOFuYIA7wtYsg52NOPiIIZlAs6pL64yENO2y5A0sPXs6hVXE1Wy+yBVdhdkWcNSzACMkcQvscnKB9VXwLKzr1vGAyoeasb7e
C:\WINDOWS\tasks\BQHUM.job - C:\Documents and Settings\Pavlna\Data aplikac\BQHUM.exe /infocmdline=wU+9lX3YEpN+jlQPYAC+lATHhh/mp8HudSSRG0zvKrvSpxFzjdyxLP45gzvPG37gY/wwxYucbbuLfSbnhVEZw6ns4vRHWcOf9dxNCj74lpV801MXXEjYmtA4H3vZz25pxc7rMkvr711oY/M+6VuTnVCfLIJTVA2jlx2VXcn3nEMI+9dgI9+wLhgrXidvAYkBXWVR48d/7sL8l61V5gIPYd5hNwOwZroLOf+Brh9rbupqB8nae2Le19+rUeW3lM3Q/ovFNR2F0qIBeTDzYR1QU9u7T4JqNRcBWIXwTQgHjXrAmgJzvc/gG9NHuEbp3oRH80y4nt+y4V0t5j8R6eBy/RBGEAL84A7lADtPaY8zePqcc8IwXnH56sVMmDhv+gSgIGeXSJIOdD/nydKUQ7sewmbF1St6VeA11ZRg9lL+wwph9VPy63hoCsBCxiR5ouwu39fcK4rhK3Hmu93TFtC5cm1l1t8aXQS8UsmLsm/qNtY6aMuTj8wh2v7SAFMsjwi0
C:\WINDOWS\tasks\DoctorPC_Popup.job - C:\Program Files\Doctor PC\Splash.exe true
C:\WINDOWS\tasks\FKVHSDS.job - C:\Documents and Settings\Pavlna\Data aplikac\FKVHSDS.exe /infocmdline=JTjCyRPIEg5fz7Idk1TBs+mjMnu0NF7lV2ezVlDB8ag+rsVVsB7saGjFKynxzGi3bekrs4jV3XOUlK0XRzumswcjc3ZoSKjwbYJQjIO3PX/MdNfpoX39evATfqlJ0dlFMDic/5nDk1KIR6QSVYR8Gby77G6t3IH6OOoqMKoVN1lxw+RnTX9dXhtGiX5GZxvdy2MiPJnj7bMsa/viwPXqaXN3eq2qewsmhxng+XWbYsPYgJQphaUAHTi7lxXHUx5o1u1OP/ImgHi6lRY+Mo5DA7xiuIwMu9DpOlLo9ltXJf42ccKjrwRDPhSUSYw6oFJ+ULqphxaHMfHPHA+E3Pwj2aM5+qy9XDVatuKicAqej7J+sw3ELpL4d9hRLtCuKbeZ7a74VrKTss/5AACzt8Bi3QLo3q2zcvJUvArDZAVi+cj0AtkgWx7LM+o5vQk4sIhsT5xMDn+vTvccRqEBhZL6GsB8J94iR2W5jXZUZtnt9o97Yr7t8puZJ6kuPKA5V6VE
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\IPZCVMDS.job - C:\Documents and Settings\Pavlna\Data aplikac\IPZCVMDS.exe /infocmdline=iIVV5AqM51PFkjzeiY/ityPS15reZAKaRX4VjQiA2r+Vif0xE/tek3jfJPuMJYwkPwVUmeWJ6/UZyHiiLVzc9FKinciESqWsIAjYM2CjZ6FcC9ixuCoCFVD3hd1coXM5s1oyjRUDair/wqgxdEIRDQ73BnQiThZVwpEjcdHuJNI7j+aWoPtZJ2JURdvMThIJgryyPNJbyI3C917GjZ0am0p4gdykNxsJfiUT4XGEEulgI/ga8VDMqoAPvC4tmchoxtF8qqJvnv1YeHq222GgYdgATAA5Ly7XYi2evPBnuqRn9dMwPc2LNzLwGPf5UdT7nOdYKiEoJeqQhqm4odlqM65K6jqlSWHJchqLLDrk0cr/jMz1gFUoSbB/k7s3ju0RvbEotQiynC+73nK/oDLYfude9o58fybVxiJeezye1/ZqRA/bGM4kCp5ZySrk235C7FDRpHUWnCho7vOH2lJzZD8TmFMYjXWpjBRTm+OVRTGDvWKyrFJKwOQh3bRTX2ZusZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\SDT.job - C:\Documents and Settings\Pavlna\Data aplikac\SDT.exe /infocmdline=cFarxy0zu1jgXAT1ge3JVkPuHnC/lepFjxWtoAu5PjVhy9cDLj2Q5pBkjdh7UK41qpCuqYvLadQEIhI40U1Qcee/lWt29EuTjaMugXduffN69oeMkYIojaGc/KybtpxrK5CQ4Kmi/E3mfuxDq2otESdjldMrk2l4/IyZ2uJ0SstVh2lIihcq35JlV73AhMHm+LkROn9j43aoBVaQtBK5Qptq0m5RVEi6m37sxYCr8axfm+u4T09P6VsPa8USG4cL4gnZsp4qy0hVK28rfhCFqvmu0McwNd/l60XzhaCAYouOGuqS7tP7UFNU4mR+FgVn7PFi5QbzSs+MclB2T3863U25eUdt7/vKWBQh3sU1qhJ2EQrfJD2SJ096RxW42kJVKxbX/W09EHDw/LXCaAljqd4VVncwfGbv6TBHrZvMWiXcmWx6HDKw1DEuGjvMUC3eZ3n+UbVMnUO4oHQmibZUeITtzVobF7i++JPX97j3o+GRh/hrr1VSTKwirPdbKFKv
C:\WINDOWS\tasks\YTVJIN.job - C:\Documents and Settings\Pavlna\Data aplikac\YTVJIN.exe /infocmdline=iG4oBdMdSoyfkqRdbbpUE6tmY/9w4IYb2lxgxq856qny9TqMwm0J9G5xanCJaWH6O9xVL6rgJhkn9Au8AXXqbJXfcTRLuU8TO/+OeO6rmyGAicOFe51G9C1EzsE8oVBPJ68v4O4HuTuHyu+HOC5o+dbNjBGb4nN1Z/OHjxW4hWfGMUMc4BM4FKnb4SZ1pDCs7DI/7kPkwa9qbxJvt+glQIy+dLeD46M8CRZcx/rS4tpD9sbXsrZFeCgw8Mz6MD4yb+Dcnk+qfBe71/pylqMn2E4g2fGQxVWYBb3yzgZD3x0MFhacquPX3yfG9iHOO/4pv2En9lkXEEd7mEFuu+wFoTGOwZY+XHpgd0G3PiufVcJuWWLuC0C8J4glXoMuVbQO0o0nrCXYZ1fMil1ryZ2sxBXg54Ox4Td/4eRzuTLve9hNoynnuyxdwCn4N8p97Db+OqujGzjz030pdppG6dfu6l4Ys1j0tDf6cABs3hMcPOfj4JwbkFn0JlCBwC5a+czY
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default
prefs.js - "Keyword.Enabled" - "true"
prefs.js - "browser.search.useDBForOrder" - false
prefs.js - "browser.startup.homepage" - "http://home.tb.ask.com/index.jhtml?ptb= ... tAodOSEATQ"
prefs.js - "keyword.URL" - "http://search.tb.ask.com/search/GGmain. ... searchfor="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw_1214154.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll
C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default\extensions\
89ffxtbr@SafePCRepair_89.com
9pffxtbr@OnlineMapFinder_9p.com
staged
veggy@veggyAddon.com
{58e3c1c9-2dc1-4762-bd45-1df9da9d0820}
{6726b74d-ed76-7f21-e782-28d509370ade}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Documents and Settings\Pavlína\Data aplikací\Mozilla\Firefox\Profiles\a7i56ps3.default\searchplugins\
ask-search.xml
ask-web-search.xml
myplaycity.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files\SupTab\SupTab.dll [2014-12-03 515464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-17 460384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9b9dcae3-be34-424c-8d73-75e305a9e091}]
Search Assistant BHO - C:\Program Files\WeatherBlink\bar\2.bin\gcSrcAs.dll [2015-05-21 144968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-17 172640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dc9051c2-8f55-479a-97a4-747980d9047f}]
Toolbar BHO - C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbar.dll [2015-05-21 1037896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{f20de5e0-2a6e-4c54-985f-1cf59551ce39} - WeatherBlink - C:\Program Files\WeatherBlink\bar\2.bin\gcbar.dll [2015-05-21 1037896]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2006-10-19 1183656]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2006-10-19 1958800]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2006-10-17 87584]
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"WeatherBlink AppIntegrator 32-bit"=C:\PROGRA~1\WEATHE~2\bar\2.bin\AppIntegrator.exe [2015-05-21 225864]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2015-04-30 334896]
"WeatherBlink Search Scope Monitor"=C:\PROGRA~1\WEATHE~2\bar\2.bin\gcsrchmn.exe /m=2 /w /h []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"cz.seznam.software.autoupdate"=C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz\bin\wszndesktop.exe [2015-05-26 103080]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"DoctorPC"=C:\Program Files\Doctor PC\DoctorPC.exe true []
"Steam"=C:\Program Files\Steam\steam.exe [2015-06-02 2892992]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
C:\Documents and Settings\Pavlína\Nabídka Start\Programy\Po spuštění
conhost32.exe
conhost64.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-15 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\GameSpy Arcade\Aphex.exe"="C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Counter-Strike 1.6 Standalone\launcher.exe"="C:\Program Files\Counter-Strike 1.6 Standalone\launcher.exe:*:Enabled:Creted by Martin.cz"
"C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe"="C:\UDK\Fps Terminator\Binaries\Win32\UDK.exe:*:Enabled:UDK"
"C:\WarThunder\launcher.exe"="C:\WarThunder\launcher.exe:*:Enabled:War Thunder launcher"
"C:\WarThunder\bpreport.exe"="C:\WarThunder\bpreport.exe:*:Enabled:War Thunder Crash Reporter"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Steam\bin\steamwebhelper.exe"="C:\Program Files\Steam\bin\steamwebhelper.exe:*:Enabled:Steam Web Helper"
"D:\team fortess2\steamapps\common\Team Fortress 2\hl2.exe"="D:\team fortess2\steamapps\common\Team Fortress 2\hl2.exe:*:Enabled:Team Fortress 2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"vidc.VP62"=vp6vfw.dll
======List of files/folders created in the last 1 month======
2015-06-03 21:35:21 ----D---- C:\Program Files\trend micro
2015-06-03 21:35:20 ----D---- C:\rsit
2015-06-03 20:36:58 ----A---- C:\Boot.bak
2015-06-03 20:36:52 ----RASHD---- C:\cmdcons
2015-06-03 20:34:30 ----A---- C:\WINDOWS\zip.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWSC.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\SWREG.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\sed.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\PEV.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\NIRCMD.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\MBR.exe
2015-06-03 20:34:30 ----A---- C:\WINDOWS\grep.exe
2015-06-03 20:34:24 ----SD---- C:\ComboFix
2015-06-03 20:34:12 ----D---- C:\Qoobox
2015-06-03 20:33:54 ----D---- C:\WINDOWS\erdnt
2015-05-23 14:17:52 ----HD---- C:\WINDOWS\PIF
2015-05-17 10:33:37 ----D---- C:\Documents and Settings\Pavlína\Data aplikací\.minecraft
2015-05-17 10:32:19 ----D---- C:\Program Files\Common Files\Java
2015-05-17 10:27:34 ----D---- C:\Program Files\Java
2015-05-17 09:30:51 ----D---- C:\Program Files\McAfee Security Scan
2015-05-16 21:18:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan
2015-05-10 13:53:41 ----D---- C:\Program Files\NVIDIA Corporation
2015-05-10 13:52:48 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
======List of files/folders modified in the last 1 month======
2015-06-03 21:35:21 ----RD---- C:\Program Files
2015-06-03 21:34:26 ----D---- C:\Program Files\Steam
2015-06-03 21:33:32 ----D---- C:\WINDOWS\Temp
2015-06-03 21:33:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-06-03 21:22:44 ----D---- C:\WINDOWS\system32\CatRoot2
2015-06-03 20:36:58 ----RASH---- C:\boot.ini
2015-06-03 20:34:30 ----D---- C:\WINDOWS
2015-06-03 20:34:25 ----D---- C:\WINDOWS\Prefetch
2015-06-03 20:34:13 ----D---- C:\WINDOWS\system32\drivers
2015-06-03 20:28:32 ----D---- C:\Documents and Settings\Pavlína\Data aplikací\Seznam.cz
2015-05-24 11:32:27 ----D---- C:\Program Files\The KMPlayer
2015-05-22 18:01:34 ----SD---- C:\Documents and Settings\Pavlína\Data aplikací\Microsoft
2015-05-17 10:32:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Oracle
2015-05-17 10:32:23 ----SHD---- C:\WINDOWS\Installer
2015-05-17 10:32:19 ----D---- C:\Program Files\Common Files
2015-05-17 10:31:56 ----D---- C:\WINDOWS\system32
2015-05-17 10:30:26 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-05-16 21:18:39 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-05-15 20:36:15 ----SD---- C:\WINDOWS\Tasks
2015-05-13 21:25:39 ----D---- C:\WINDOWS\system32\MRT
2015-05-13 21:19:48 ----A---- C:\WINDOWS\system32\MRT.exe
2015-05-10 13:54:49 ----D---- C:\WINDOWS\system32\DirectX
2015-05-10 13:54:48 ----HD---- C:\WINDOWS\inf
2015-05-10 13:54:26 ----RSD---- C:\WINDOWS\assembly
2015-05-10 13:52:46 ----D---- C:\WINDOWS\WinSxS
2015-05-10 09:18:26 ----HD---- C:\Program Files\InstallShield Installation Information
2015-05-10 09:18:18 ----D---- C:\Program Files\Activision
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\System32\DRIVERS\snapman.sys [2014-08-13 114048]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\System32\DRIVERS\timntr.sys [2014-08-13 395744]
R1 {6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt;{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt; C:\WINDOWS\system32\drivers\{6ae56b3b-b4e1-47bb-8719-04f47e9feb4d}Gt.sys [2014-12-03 55824]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [2014-08-13 39264]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-09-21 2278784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-12-15 1463296]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2008-07-25 176640]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 cpuz134;cpuz134; \??\C:\DOCUME~1\PAVLNA~1\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2006-10-17 230944]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2005-12-15 405504]
R2 IePluginServices;IePlugin Services; C:\Documents and Settings\All Users\Data aplikací\IePluginServices\PluginService.exe [2014-12-03 715656]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-12-14 520192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S2 Update Rad Rater;Update Rad Rater; C:\Program Files\Rad Rater\updateRadRater.exe []
S2 WeatherBlinkService;WeatherBlinkService; C:\PROGRA~1\WEATHE~2\bar\2.bin\gcbarsvc.exe [2015-05-21 90696]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-16 268464]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-09-20 116648]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 235696]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2015-03-11 114800]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------