Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu logu,asi mam virus.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Prosim o kontrolu logu,asi mam virus.

#1 Příspěvek od miso25 »

Dobry den,moj problem je v tom ze ked pocitac necham v klude nic nerobim nehybem s mysou tak za cca 2 min mi teploty stupnu ako keby som hral hru proste grafika mi z 42 stupnov za 2 min. stupne na 64 a procesor tak isto co nie je ako fakt normalne ale ako nahle pohnem z mysou a zacnem pracovat na pc teploty pomaly klesnu na svoje hodnoty.poprosil by som vas o radu prikladam vypis z logu. dakujem Logfile of random's system information tool 1.08 (written by random/random)
Run by pc at 2013-06-12 19:20:35
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 38 GB (21%) free of 180 GB
Total RAM: 6142 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:20:36, on 12. 6. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16490)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\BitTorrent\bittorrent.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Program Files\trend micro\pc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
R3 - URLSearchHook: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (file missing)
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Keyword Search - {31A0D938-3055-46BA-8919-59E44E0D7E51} - C:\Program Files (x86)\Keyword Search\torangcomz.dll (file missing)
O2 - BHO: ·çĐĐĘÓƵ˛Ą·ĹĽ°ĎÂÔŘ×éĽţ - {4ADBABBD-E1CA-4f11-BD01-73B0B6E4B5BA} - C:\Users\pc\funshion\funshiontools\FunshionHelper.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
O2 - BHO: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (file missing)
O2 - BHO: TopSpaceHelper - {C8625893-2C0F-4484-8C18-52B00D5A8BB9} - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll (file missing)
O3 - Toolbar: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared files\brs.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WJNews_2013511] "C:\Program Files\Wuji\2013511\WJPap.exe" -mini
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [KeywordSearchUpdater] C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Keyboard Inf.] C:\Users\pc\AppData\Roaming\runic games\msdn.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3719279243-3044573747-122376168-1006\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: SimilarWeb - {5D06ED6E-DA78-4486-A246-B131A2C39807} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Baidu Updater (BaiduUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate1cac0be77e89afe) (gupdate1cac0be77e89afe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PC Speed Up Service (PCSUService) - Unknown owner - C:\Program Files (x86)\Zrychlenie PC\PCSUService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11092 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k rpcss
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files (x86)\Zrychlenie PC\PCSUService.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
taskeng.exe {EC052BDF-391D-447F-8E26-DC547A575028}
"C:\Windows\system32\Dwm.exe"
taskeng.exe {AB633949-C457-4775-A322-A36BBB63AD41}
C:\Windows\Explorer.EXE
"C:\Windows\RAVCpl64.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Windows\ehome\ehtray.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Users\pc\AppData\Roaming\runic games\msdn.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\brs.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" /NOINSTALL
"Taskmgr.exe"
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2364.fa6af00.1989287678 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 2364 "\\.\pipe\gecko-crash-server-pipe.2364" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe" --proxy-stub-channel=Flash3952.6AC2BDE0.13435 --host-broker-channel=Flash3952.6AC2BDE0.3956 --host-pid=3952 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe" --channel=4732.003BF5AC.72369040 --proxy-stub-channel=Flash3952.6AC2BDE0.13435 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll" --host-npapi-version=27 --type=renderer
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 692 696 704 65536 700
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"D:\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31A0D938-3055-46BA-8919-59E44E0D7E51}]
Keyword Search - C:\Program Files (x86)\Keyword Search\torangcomz.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ADBABBD-E1CA-4f11-BD01-73B0B6E4B5BA}]
·çĐĐĘÓƵ˛Ą·ĹĽ°ĎÂÔŘ×éĽţ - C:\Users\pc\funshion\funshiontools\FunshionHelper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-04 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
BitTorrentBar Toolbar - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll [2010-10-18 3908192]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Hot MP3 Toolbar - C:\Program Files (x86)\Hot_MP3\tbHot_.dll [2010-02-22 2353176]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}]
MyAshampoo Toolbar - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8625893-2C0F-4484-8C18-52B00D5A8BB9}]
TopSpaceHelper Class - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-04 171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{9384bd4c-dd14-4be9-80f7-f6277511e4f5} - Hot MP3 Toolbar - C:\Program Files (x86)\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - BitTorrentBar Toolbar - C:\Program Files (x86)\BitTorrentBar\tbBitT.dll [2010-10-18 3908192]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - MyAshampoo Toolbar - C:\Program Files (x86)\MyAshampoo\tbMyAs.dll []
{74198672-5F7D-4FE9-A611-4AC1D5A66A15} - SimilarWeb - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll [2013-01-28 320888]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2008-07-24 6452256]
"Skytel"=C:\Windows\Skytel.exe [2008-07-24 1833504]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2013-06-07 1641896]
"KeywordSearchUpdater"=C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []
"Keyboard Inf."=C:\Users\pc\AppData\Roaming\runic games\msdn.exe [2013-06-09 5178368]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"RemoteControl9"=C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-07-06 87336]
"PDVD9LanguageShortcut"=C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [2009-04-27 50472]
"BDRegion"=C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [2009-11-19 75048]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"WJNews_2013511"=C:\Program Files\Wuji\2013511\WJPap.exe -mini []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes3\deskscapes.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\BitTorrent\bittorrent.exe"="C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2013-06-12 19:14:33 ----D---- C:\rsit
2013-06-12 19:14:33 ----D---- C:\Program Files\trend micro
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-06-12 17:59:21 ----A---- C:\Windows\system32\mshtmled.dll
2013-06-12 17:59:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-06-12 17:59:20 ----A---- C:\Windows\system32\ieui.dll
2013-06-12 17:59:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-06-12 17:59:19 ----A---- C:\Windows\system32\jsproxy.dll
2013-06-12 17:59:19 ----A---- C:\Windows\system32\ieUnatt.exe
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\url.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\url.dll
2013-06-12 17:59:17 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\vbscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\jscript.dll
2013-06-12 17:59:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-06-12 17:59:15 ----A---- C:\Windows\system32\iertutil.dll
2013-06-12 17:59:14 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\ieframe.dll
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\certutil.exe
2013-06-12 17:55:05 ----A---- C:\Windows\system32\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\system32\certutil.exe
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\certenc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\certenc.dll
2013-06-12 17:53:52 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2013-06-12 17:53:52 ----A---- C:\Windows\system32\cryptdlg.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\printcom.dll
2013-06-12 17:53:51 ----A---- C:\Windows\system32\win32spl.dll
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)\SpeedFan
2013-05-18 02:01:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-17 22:41:01 ----D---- C:\Users\pc\AppData\Roaming\Arrowhead
2013-05-17 22:40:57 ----D---- C:\Windows\9530AE42DAE146199594B23487285D17.TMP
2013-05-16 00:11:23 ----A---- C:\Windows\system32\win32k.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\cdd.dll

======List of files/folders modified in the last 1 months======

2013-06-12 19:20:33 ----D---- C:\Windows\Temp
2013-06-12 19:17:20 ----D---- C:\Users\pc\AppData\Roaming\BitTorrent
2013-06-12 19:14:33 ----RD---- C:\Program Files
2013-06-12 19:05:25 ----SHD---- C:\System Volume Information
2013-06-12 18:55:49 ----D---- C:\Windows\rescache
2013-06-12 18:48:32 ----D---- C:\Windows\Microsoft.NET
2013-06-12 18:48:01 ----D---- C:\Program Files (x86)\Steam
2013-06-12 18:47:35 ----SHD---- C:\Windows\Installer
2013-06-12 18:47:30 ----RSD---- C:\Windows\assembly
2013-06-12 18:44:13 ----D---- C:\Windows\System32
2013-06-12 18:44:13 ----D---- C:\Windows\inf
2013-06-12 18:44:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-06-12 18:38:16 ----D---- C:\Windows\Prefetch
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\en-US
2013-06-12 18:35:08 ----D---- C:\Windows\SysWOW64
2013-06-12 18:35:08 ----D---- C:\Windows\system32\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\system32\en-US
2013-06-12 18:35:07 ----D---- C:\Windows\system32\drivers
2013-06-12 18:35:06 ----D---- C:\Windows\SYSWOW64\migration
2013-06-12 18:35:06 ----D---- C:\Windows\system32\migration
2013-06-12 18:35:06 ----D---- C:\Program Files (x86)\Internet Explorer
2013-06-12 18:35:05 ----D---- C:\Program Files\Internet Explorer
2013-06-12 18:26:26 ----D---- C:\ProgramData\Microsoft Help
2013-06-12 18:25:50 ----D---- C:\Windows\winsxs
2013-06-12 18:22:52 ----D---- C:\Windows\Debug
2013-06-12 18:22:51 ----A---- C:\Windows\system32\mrt.exe
2013-06-12 18:22:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-06-12 17:59:50 ----D---- C:\Windows\system32\catroot
2013-06-12 17:59:47 ----D---- C:\Windows\system32\catroot2
2013-06-12 16:50:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-06-11 20:34:18 ----D---- C:\Windows
2013-06-11 20:34:18 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-06-11 20:33:20 ----SD---- C:\ProgramData\Microsoft
2013-06-11 20:33:20 ----D---- C:\Windows\Tasks
2013-06-11 14:01:33 ----D---- C:\Users\pc\AppData\Roaming\vlc
2013-06-09 01:39:23 ----D---- C:\Users\pc\AppData\Roaming\runic games
2013-06-09 01:17:48 ----D---- C:\Users\pc\AppData\Roaming\NationRed
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)
2013-05-18 07:17:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2008-11-04 98144]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-31 834544]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/03/19 01:30:04]; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-02-28 146928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-08-11 72216]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2008-07-24 1488032]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-08-11 11552]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-03-15 11048736]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2009-03-17 196096]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 87040]
S1 archlp;archlp; SysWOW64\drivers\archlp.sys []
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys []
S2 tandpl;tandpl; C:\Windows\System32\drivers\tandpl.sys []
S3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [2012-05-30 28320]
S3 as5e0qrc;as5e0qrc; C:\Windows\system32\drivers\as5e0qrc.sys []
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 cpuz135;cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 6144]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-04-22 12744]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-06-05 24104]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 11008]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 7936]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS_64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2009-05-08 602624]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 115240]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 19496]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 158760]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 137256]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 34344]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 136744]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 151592]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-04-11 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 46592]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 198656]
S3 X6va005;X6va005; \??\C:\Users\pc\AppData\Local\Temp\005656F.tmp []
S3 X6va006;X6va006; \??\C:\Users\pc\AppData\Local\Temp\006721B.tmp []
S3 xnacc;XBOX 360 Controller For Windows Driver Service; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 903168]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-04-08 68992]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 8704]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 438328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 27648]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-03-15 877856]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-15 1266464]
R2 PCSUService;PC Speed Up Service; C:\Program Files (x86)\Zrychlenie PC\PCSUService.exe [2011-09-28 234720]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-07 543656]
S2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
S2 FunshionSvr;FSServicePlatform; C:\Windows\System32\svchost.exe [2008-01-21 27648]
S2 gupdate1cac0be77e89afe;Služba Google Update (gupdate1cac0be77e89afe); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12 256904]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 BaiduUpdater;Baidu Updater; C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe []
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-08-15 130976]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-18 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://www.stahuj.centrum.cz/utility_a_ ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte na Search (hledat)
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#3 Příspěvek od miso25 »

AdwCleaner v2.303 - Log vytvorený 12/06/2013 o 20:23:18
# Aktualizované 08/06/2013 Xplode
# Operaený systém : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Uživateľ : pc - PC-PC
# Spustený systém : Normálny
# Spustené z : D:\Downloads\adwcleaner.exe
# Voľba [Prehľada?]


***** [Služby] *****

Nájdené : FunshionSvr
Nájdené : PCSUService

***** [Súbory / Adresáre] *****

Adresár Nájdené : C:\Program Files (x86)\BitTorrentBar
Adresár Nájdené : C:\Program Files (x86)\Conduit
Adresár Nájdené : C:\Program Files (x86)\ConduitEngine
Adresár Nájdené : C:\Program Files (x86)\Hot_MP3
Adresár Nájdené : C:\Program Files (x86)\SimilarSites
Adresár Nájdené : C:\ProgramData\Trymedia
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\BitTorrentBar
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\Conduit
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\ConduitEngine
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\Hot_MP3
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\MyAshampoo
Adresár Nájdené : C:\Users\pc\AppData\LocalLow\PriceGong
Adresár Nájdené : C:\Users\pc\AppData\Roaming\Desktopicon
Adresár Nájdené : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\Conduit
Adresár Nájdené : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\ConduitCommon
Adresár Nájdené : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\CT2790392
Adresár Nájdené : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
Adresár Nájdené : C:\Users\pc\AppData\Roaming\SimilarSites
Súbor Nájdené : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\searchplugins\Conduit.xml

***** [Registre] *****

Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Nájdené : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Nájdené : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Nájdené : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Nájdené : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Nájdené : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Kľúe Nájdené : HKCU\Software\APN PIP
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\BitTorrentBar
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\Conduit
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\conduitEngine
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\conduitEngine
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\Hot_MP3
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\MyAshampoo
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\MyAshampoo\toolbar
Kľúe Nájdené : HKCU\Software\AppDataLow\Software\PriceGong
Kľúe Nájdené : HKCU\Software\AppDataLow\Toolbar
Kľúe Nájdené : HKCU\Software\Conduit
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BitTorrentBar Toolbar
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Hot_MP3 Toolbar
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyAshampoo Toolbar
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D382FE6-D448-41B2-A701-64DA06ACC6EC}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3FAF4281-AA13-4196-8CDD-BB4A89C01D04}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{685E2007-F722-4D48-BC42-5FAA692CF1B2}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7525BAEF-1A1A-40BA-9C47-09C91A8E37B8}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKCU\Software\PIP
Kľúe Nájdené : HKCU\Software\Softonic
Kľúe Nájdené : HKCU\Software\TENCENT
Kľúe Nájdené : HKCU\Software\YahooPartnerToolbar
Kľúe Nájdené : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Kľúe Nájdené : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Kľúe Nájdené : HKLM\Software\BitTorrentBar
Kľúe Nájdené : HKLM\SOFTWARE\Classes\Conduit.Engine
Kľúe Nájdené : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Kľúe Nájdené : HKLM\SOFTWARE\Classes\Toolbar.CT1066435
Kľúe Nájdené : HKLM\SOFTWARE\Classes\Toolbar.CT2475029
Kľúe Nájdené : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Kľúe Nájdené : HKLM\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}
Kľúe Nájdené : HKLM\Software\Conduit
Kľúe Nájdené : HKLM\Software\conduitEngine
Kľúe Nájdené : HKLM\Software\conduitEngine
Kľúe Nájdené : HKLM\Software\Hot_MP3
Kľúe Nájdené : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0D35EE00-A057-488B-A7C2-24C4713B2BC0}
Kľúe Nájdené : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A408D3B0-61A5-4D46-AE04-4D8A5E838AB2}
Kľúe Nájdené : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA1412E1-B190-4E95-90E2-3D04B728699B}
Kľúe Nájdené : HKLM\Software\MyAshampoo
Kľúe Nájdené : HKLM\Software\MyAshampoo\toolbar
Kľúe Nájdené : HKLM\Software\PIP
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0D35EE00-A057-488B-A7C2-24C4713B2BC0}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1D382FE6-D448-41B2-A701-64DA06ACC6EC}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3FAF4281-AA13-4196-8CDD-BB4A89C01D04}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{685E2007-F722-4D48-BC42-5FAA692CF1B2}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7525BAEF-1A1A-40BA-9C47-09C91A8E37B8}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A408D3B0-61A5-4D46-AE04-4D8A5E838AB2}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CA1412E1-B190-4E95-90E2-3D04B728699B}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{23F14776-18FF-405D-AA2C-90C5AE2F77A5}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E5D04B7-415D-4F0A-9855-B604128FED8C}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E09B09D-25AB-427A-A64C-24AAD112D693}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentBar Toolbar
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Kľúe Nájdené : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hot_MP3 Toolbar
Kľúe Nájdené : HKLM\SOFTWARE\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}
Kľúe Nájdené : HKU\S-1-5-21-3719279243-3044573747-122376168-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Kľúe Nájdené : HKU\S-1-5-21-3719279243-3044573747-122376168-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}

***** [Internetové prehliadaee] *****

-\\ Internet Explorer v9.0.8112.16490

[OK] Registre sú eisté.

-\\ Mozilla Firefox v21.0 (sk)

Súbor : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\prefs.js

Nájdené : user_pref("CT2790392..clientLogIsEnabled", false);
Nájdené : user_pref("CT2790392..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Nájdené : user_pref("CT2790392..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Nájdené : user_pref("CT2790392.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Nájdené : user_pref("CT2790392.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Nájdené : user_pref("CT2790392.AppTrackingLastCheckTime", "Fri Aug 24 2012 14:00:48 GMT+0200");
Nájdené : user_pref("CT2790392.BrowserCompStateIsOpen_129633547190125290", true);
Nájdené : user_pref("CT2790392.BrowserCompStateIsOpen_130059329278017115", true);
Nájdené : user_pref("CT2790392.BrowserCompStateIsOpen_1359634298000", true);
Nájdené : user_pref("CT2790392.CTID", "CT2790392");
Nájdené : user_pref("CT2790392.CurrentServerDate", "12-6-2013");
Nájdené : user_pref("CT2790392.DialogsAlignMode", "LTR");
Nájdené : user_pref("CT2790392.DialogsGetterLastCheckTime", "Thu Jun 06 2013 21:54:55 GMT+0200");
Nájdené : user_pref("CT2790392.DownloadReferralCookieData", "");
Nájdené : user_pref("CT2790392.EMailNotifierPollDate", "Wed Jun 12 2013 20:12:43 GMT+0200");
Nájdené : user_pref("CT2790392.FeedLastCount129313977501788460", 550);
Nájdené : user_pref("CT2790392.FeedPollDate129313974171006416", "Wed Jun 12 2013 18:51:11 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313975698350231", "Wed Jun 12 2013 18:51:11 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313976370850190", "Wed Jun 12 2013 18:51:11 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313976648818968", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313977444757117", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313980389131455", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313980655381977", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313980886163259", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313981234756535", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313983226631720", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedPollDate129313983607725691", "Wed Jun 12 2013 18:51:12 GMT+0200");
Nájdené : user_pref("CT2790392.FeedTTL129313974171006416", 10);
Nájdené : user_pref("CT2790392.FeedTTL129313975698350231", 5);
Nájdené : user_pref("CT2790392.FeedTTL129313977444757117", 15);
Nájdené : user_pref("CT2790392.FeedTTL129313980655381977", 5);
Nájdené : user_pref("CT2790392.FeedTTL129313981234756535", 5);
Nájdené : user_pref("CT2790392.FirstServerDate", "20-11-2010");
Nájdené : user_pref("CT2790392.FirstTime", true);
Nájdené : user_pref("CT2790392.FirstTimeFF3", true);
Nájdené : user_pref("CT2790392.FixPageNotFoundErrors", false);
Nájdené : user_pref("CT2790392.GroupingServerCheckInterval", 1440);
Nájdené : user_pref("CT2790392.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Nájdené : user_pref("CT2790392.HasUserGlobalKeys", true);
Nájdené : user_pref("CT2790392.HomePageProtectorEnabled", false);
Nájdené : user_pref("CT2790392.Initialize", true);
Nájdené : user_pref("CT2790392.InitializeCommonPrefs", true);
Nájdené : user_pref("CT2790392.InstallationAndCookieDataSentCount", 3);
Nájdené : user_pref("CT2790392.InstallationType", "UnknownIntegration");
Nájdené : user_pref("CT2790392.InstalledDate", "Sat Nov 20 2010 12:52:12 GMT+0100");
Nájdené : user_pref("CT2790392.IsAlertDBUpdated", true);
Nájdené : user_pref("CT2790392.IsGrouping", false);
Nájdené : user_pref("CT2790392.IsMulticommunity", false);
Nájdené : user_pref("CT2790392.IsOpenThankYouPage", true);
Nájdené : user_pref("CT2790392.IsOpenUninstallPage", false);
Nájdené : user_pref("CT2790392.LanguagePackLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Nájdené : user_pref("CT2790392.LanguagePackReloadIntervalMM", 1440);
Nájdené : user_pref("CT2790392.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Nájdené : user_pref("CT2790392.LastLogin_3.10.0.1", "Tue Apr 17 2012 17:57:38 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.12.0.7", "Tue Apr 24 2012 20:39:00 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.12.2.3", "Thu May 31 2012 01:11:38 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.13.0.6", "Tue Jul 17 2012 19:48:18 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.14.1.0", "Tue Aug 28 2012 16:51:07 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.15.1.0", "Wed Nov 07 2012 14:57:49 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.16.0.3", "Mon Mar 04 2013 19:42:35 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.18.0.7", "Wed Jun 12 2013 20:12:43 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.2.3.3", "Tue Mar 22 2011 16:08:11 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.3.3.2", "Thu Jun 23 2011 11:25:44 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.5.0.12", "Tue Aug 16 2011 23:07:54 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.6.0.10", "Fri Sep 23 2011 07:42:44 GMT+0200");
Nájdené : user_pref("CT2790392.LastLogin_3.7.0.6", "Wed Nov 09 2011 12:51:57 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.8.0.8", "Tue Dec 06 2011 13:06:03 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.8.1.0", "Wed Jan 11 2012 19:57:56 GMT+0100");
Nájdené : user_pref("CT2790392.LastLogin_3.9.0.3", "Thu Mar 08 2012 15:02:54 GMT+0100");
Nájdené : user_pref("CT2790392.LatestVersion", "3.18.0.7");
Nájdené : user_pref("CT2790392.Locale", "en");
Nájdené : user_pref("CT2790392.MCDetectTooltipHeight", "83");
Nájdené : user_pref("CT2790392.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Nájdené : user_pref("CT2790392.MCDetectTooltipWidth", "295");
Nájdené : user_pref("CT2790392.MyStuffEnabledAtInstallation", true);
Nájdené : user_pref("CT2790392.SHRINK_TOOLBAR", 1);
Nájdené : user_pref("CT2790392.SearchEngineBeforeUnload", "Google");
Nájdené : user_pref("CT2790392.SearchFromAddressBarIsInit", true);
Nájdené : user_pref("CT2790392.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT279[...]
Nájdené : user_pref("CT2790392.SearchInNewTabEnabled", true);
Nájdené : user_pref("CT2790392.SearchInNewTabIntervalMM", 1440);
Nájdené : user_pref("CT2790392.SearchInNewTabLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Nájdené : user_pref("CT2790392.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Nájdené : user_pref("CT2790392.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Nájdené : user_pref("CT2790392.SearchProtectorEnabled", false);
Nájdené : user_pref("CT2790392.SearchProtectorToolbarDisabled", false);
Nájdené : user_pref("CT2790392.ServiceMapLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Nájdené : user_pref("CT2790392.SettingsLastCheckTime", "Wed Jun 12 2013 18:51:11 GMT+0200");
Nájdené : user_pref("CT2790392.SettingsLastUpdate", "1371024743");
Nájdené : user_pref("CT2790392.ThirdPartyComponentsInterval", 504);
Nájdené : user_pref("CT2790392.ThirdPartyComponentsLastCheck", "Thu Jun 06 2013 02:02:43 GMT+0200");
Nájdené : user_pref("CT2790392.ThirdPartyComponentsLastUpdate", "1331805997");
Nájdené : user_pref("CT2790392.ToolbarShrinkedFromSetup", false);
Nájdené : user_pref("CT2790392.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2790392");
Nájdené : user_pref("CT2790392.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Nájdené : user_pref("CT2790392.UserID", "UN95743413213082986");
Nájdené : user_pref("CT2790392.ValidationData_Search", 2);
Nájdené : user_pref("CT2790392.ValidationData_Toolbar", 2);
Nájdené : user_pref("CT2790392.WeatherNetwork", "");
Nájdené : user_pref("CT2790392.WeatherPollDate", "Wed Jun 12 2013 20:12:43 GMT+0200");
Nájdené : user_pref("CT2790392.WeatherUnit", "C");
Nájdené : user_pref("CT2790392.alertChannelId", "1182482");
Nájdené : user_pref("CT2790392.appApproved.129309578575850709", true);
Nájdené : user_pref("CT2790392.backendstorage./9b+7e+x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e,x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e-x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e.:2z527", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e.x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e/x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e06cg5el8:", "6E6D6B716F6D75737071");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473717775737B797677242F4B4947[...]
Nájdené : user_pref("CT2790392.backendstorage./9b+7e0x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e1x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e2x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e3x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e4x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e5x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e6x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e7x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e8x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e9x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e:x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e;x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e<x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e=x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e>x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e?x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7e@x305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7eax305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Nájdené : user_pref("CT2790392.backendstorage./9b+7ebx305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7ecx305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7edx305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b+7etx305", "2423");
Nájdené : user_pref("CT2790392.backendstorage./9b-0?3g>d", "3D3B6B3C414372437A70464678207C4A777B25214D7C242A25[...]
Nájdené : user_pref("CT2790392.backendstorage./9b-0?3g@6:5;", "");
Nájdené : user_pref("CT2790392.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Nájdené : user_pref("CT2790392.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Nájdené : user_pref("CT2790392.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
Nájdené : user_pref("CT2790392.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...]
Nájdené : user_pref("CT2790392.backendstorage./9b5ba==9cjag", "66706B3E71416D417A7143727679497A497B202252");
Nájdené : user_pref("CT2790392.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6A717370706D6E77777978");
Nájdené : user_pref("CT2790392.backendstorage./9b9643g3/9e", "6A");
Nájdené : user_pref("CT2790392.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
Nájdené : user_pref("CT2790392.backendstorage./9b<:222h64<", "393F352F3E");
Nájdené : user_pref("CT2790392.backendstorage./9b<:222h64<l8daj", "6D70706F7674737975772A7973727C7C757B7A");
Nájdené : user_pref("CT2790392.backendstorage./9b=+03eh8h8j?:", "4443");
Nájdené : user_pref("CT2790392.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Nájdené : user_pref("CT2790392.backendstorage./9b?b0d:8aj62<h", "6D");
Nájdené : user_pref("CT2790392.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Nájdené : user_pref("CT2790392.backendstorage.cb", "31");
Nájdené : user_pref("CT2790392.backendstorage.cb_experience_000", "323532");
Nájdené : user_pref("CT2790392.backendstorage.cb_firstuse0100", "31");
Nájdené : user_pref("CT2790392.backendstorage.cb_user_id_000", "43423938373035313433353934395F46697265666F78")[...]
Nájdené : user_pref("CT2790392.backendstorage.cb_user_id_002", "43423834353432323939313332335F46697265666F78")[...]
Nájdené : user_pref("CT2790392.backendstorage.cbcountry_000", "4E4C");
Nájdené : user_pref("CT2790392.backendstorage.cbcountry_001", "534B");
Nájdené : user_pref("CT2790392.backendstorage.cbfirsttime", "5765642053657020323820323031312031313A30363A31302[...]
Nájdené : user_pref("CT2790392.backendstorage.cbopenmamsettings", "30");
Nájdené : user_pref("CT2790392.backendstorage.facebook_mode", "32");
Nájdené : user_pref("CT2790392.backendstorage.facebook_user_locale", "656E");
Nájdené : user_pref("CT2790392.backendstorage.first_use_pending", "66616C7365");
Nájdené : user_pref("CT2790392.backendstorage.for_aoi", "31333033313136323234");
Nájdené : user_pref("CT2790392.backendstorage.for_ccid", "4272617469736C617661");
Nájdené : user_pref("CT2790392.backendstorage.for_cdtr", "31333034363835323139");
Nájdené : user_pref("CT2790392.backendstorage.for_cdtr6", "31333135353538323737");
Nájdené : user_pref("CT2790392.backendstorage.for_cid", "534B");
Nájdené : user_pref("CT2790392.backendstorage.for_ip", "37382E39392E35312E313735");
Nájdené : user_pref("CT2790392.backendstorage.for_lcut", "31333731303435393930");
Nájdené : user_pref("CT2790392.backendstorage.for_rid", "3032");
Nájdené : user_pref("CT2790392.backendstorage.for_zoneid", "37383136");
Nájdené : user_pref("CT2790392.backendstorage.hxxp://conduit_priceblink_com/conduit.uid", "34666532383936392D3[...]
Nájdené : user_pref("CT2790392.backendstorage.hxxp://staging_priceblink_com/conduit.uid", "39643833613534392D3[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_appsdata", "7B2261707073223A5B7B226964223A225072696365476[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_appsdefaultenabled", "6E756C6C");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_appstate_couponbuddy", "6F6E");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_appstate_pricegong", "6F6E");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_appstatereporttime", "31333731303630373634393134");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_configuration", "7B22636F6E66696775726174696F6E223A5B7B22[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_currentversion", "312E382E302E34");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_first_time", "31");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_lastlogintime", "31333731303630373635313938");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_localization", "7B22676164676574436F6E74656E74506F6C69637[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.0.4", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.3.1", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.3.2", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.4.6", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.6.0.1", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_settings1.8.0.4", "7B22537461747573223A227375636365656465[...]
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_showclosebutton", "74727565");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_showwelcomegadget", "66616C7365");
Nájdené : user_pref("CT2790392.backendstorage.mam_gk_userid", "32346662623633342D303138372D346332332D393265612[...]
Nájdené : user_pref("CT2790392.backendstorage.pairingkey", "33314444343241434438303642363539364345323037354336[...]
Nájdené : user_pref("CT2790392.backendstorage.pg_enable", "74727565");
Nájdené : user_pref("CT2790392.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Nájdené : user_pref("CT2790392.backendstorage.searchappstate", "33");
Nájdené : user_pref("CT2790392.backendstorage.searchapptracking", "31");
Nájdené : user_pref("CT2790392.backendstorage.undefined", "4672692046656220303320323031322031343A31393A3235204[...]
Nájdené : user_pref("CT2790392.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E736B2F75726C3[...]
Nájdené : user_pref("CT2790392.backendstorage.url_history0001", "687474703A2F2F666F72756D2E766972792E637A2F766[...]
Nájdené : user_pref("CT2790392.backendstorage.uttorrents", "7B226275696C64223A32383730362C226C6162656C223A5B5D[...]
Nájdené : user_pref("CT2790392.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Nájdené : user_pref("CT2790392.globalFirstTimeInfoLastCheckTime", "Sun Jun 09 2013 00:36:18 GMT+0200");
Nájdené : user_pref("CT2790392.homepageProtectorEnableByLogin", true);
Nájdené : user_pref("CT2790392.initDone", true);
Nájdené : user_pref("CT2790392.isAppTrackingManagerOn", false);
Nájdené : user_pref("CT2790392.myStuffEnabled", true);
Nájdené : user_pref("CT2790392.myStuffPublihserMinWidth", 400);
Nájdené : user_pref("CT2790392.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Nájdené : user_pref("CT2790392.myStuffServiceIntervalMM", 1440);
Nájdené : user_pref("CT2790392.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Nájdené : user_pref("CT2790392.oldAppsList", "129298377186075601,129298377186388102,1000234,129791371079091292[...]
Nájdené : user_pref("CT2790392.revertSettingsEnabled", true);
Nájdené : user_pref("CT2790392.searchProtectorDialogDelayInSec", 10);
Nájdené : user_pref("CT2790392.searchProtectorEnableByLogin", true);
Nájdené : user_pref("CT2790392.testingCtid", "");
Nájdené : user_pref("CT2790392.toolbarAppMetaDataLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Nájdené : user_pref("CT2790392.toolbarContextMenuLastCheckTime", "Thu May 30 2013 00:22:04 GMT+0200");
Nájdené : user_pref("CT2790392.usagesFlag", 2);
Nájdené : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "");
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=1182482&fid=1178159", "\"0\[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=909619&fid=905414", "\"0\""[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1182482/1178159/SK", "\"0\"[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/SK", "\"0\"")[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2475029", [...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2790392", [...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.engine.conduit-services.com/apps/TranslatedApps.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2475029",[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2790392",[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=11/8/20[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/21/2[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/27/2[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/30/2[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/20[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2790392&octid=[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/?ctid=CT2790392&octid=CT[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2475029/CT2475029[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"4f3[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/1344951.xml", "\"7e980a8f68c25685ee06[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/16887175.xml", "\"49e64dfe80b4e799239[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/17151925.xml", "\"4c29e33e2f421035216[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20536157.xml", "\"4a2d9edd9129fe92ff8[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/30261067.xml", "\"b62a911cf815e6dc217[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/34655603.xml", "\"2616c8c0e421179da1e[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/759251.xml", "\"dcb0590fabf0766b00f63[...]
Nájdené : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/816653.xml", "\"c10137f6c5f383ff1d244[...]
Nájdené : user_pref("CommunityToolbar.EngineOwner", "");
Nájdené : user_pref("CommunityToolbar.EngineOwnerGuid", "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}");
Nájdené : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar");
Nájdené : user_pref("CommunityToolbar.IsEngineShown", true);
Nájdené : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Nájdené : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\pc\\AppData\\Roaming\\Mozilla\\Fire[...]
Nájdené : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.18.0.7");
Nájdené : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Nájdené : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://facebook.conduitapps.com/v3.13/gadget.html", [...]
Nájdené : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://youtube.conduitapps.com/v115/gadget.php?appMo[...]
Nájdené : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2790392");
Nájdené : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}");
Nájdené : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar");
Nájdené : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://slirsredirect.search.aol.com/slir[...]
Nájdené : user_pref("CommunityToolbar.ToolbarsList", "CT2790392");
Nájdené : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2790392");
Nájdené : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Wed Mar 23 2011 15:26:49 GMT+01[...]
Nájdené : user_pref("CommunityToolbar.alert.alertEnabled", true);
Nájdené : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Nájdené : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Jun 23 2011 11:25:52 GMT+0200");
Nájdené : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Nájdené : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
Nájdené : user_pref("CommunityToolbar.alert.locale", "en");
Nájdené : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Nájdené : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Jun 23 2011 11:25:44 GMT+0200");
Nájdené : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Nájdené : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Nájdené : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Nájdené : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Nájdené : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Nájdené : user_pref("CommunityToolbar.alert.userId", "7431bc77-5dd7-4744-b15f-eb6ca9a6c58b");
Nájdené : user_pref("CommunityToolbar.facebook.sessionKey", "2.AQC4WwHr2qNSGXaO.86400.1322913600.0-10000104862[...]
Nájdené : user_pref("CommunityToolbar.facebook.sessionSecret", "6_HlVxYU1LwJnAKOYzlEEQ__");
Nájdené : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue Apr 17 2012 17:57:37 GMT+0200");
Nájdené : user_pref("CommunityToolbar.facebook.userId", "100001048620214");
Nájdené : user_pref("CommunityToolbar.globalUserId", "be2a8d9d-c9fd-43d9-99e4-cd42a5952dc6");
Nájdené : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Nájdené : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Nájdené : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
Nájdené : user_pref("CommunityToolbar.killedEngine", true);
Nájdené : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jun 05 2013 21:09:3[...]
Nájdené : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Nájdené : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Nájdené : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Jun 12 2013 16:06:35 GMT+020[...]
Nájdené : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Nájdené : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Nájdené : user_pref("CommunityToolbar.notifications.locale", "en");
Nájdené : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Nájdené : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jun 12 2013 16:06:28 GMT+0200");
Nájdené : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Nájdené : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Nájdené : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Nájdené : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Nájdené : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Nájdené : user_pref("CommunityToolbar.notifications.userId", "55c50faf-1e33-4971-91fc-cf102e6a9622");
Nájdené : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200"[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_16887175.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_17151925.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_20536157.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_30261067.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_34655603.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_759251.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200")[...]
Nájdené : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200")[...]
Nájdené : user_pref("CommunityToolbar.undefined", "");
Nájdené : user_pref("browser.search.defaultenginename", "Winamp Search");
Nájdené : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
Nájdené : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&Sea[...]
Nájdené : user_pref("keyword.URL", "hxxp://slirsredirect.search.aol.com/slirs_hxxp/sredir?sredir=2685&invocati[...]
Nájdené : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");

-\\ Google Chrome v27.0.1453.110

Súbor : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Súbor je eistý.

-\\ Chromium v directory_upgrade: true
}

Súbor : C:\Users\pc\AppData\Local\Chromium\User Data\Default\Preferences

[OK] Súbor je eistý.

*************************

AdwCleaner[R1].txt - [45468 octets] - [12/06/2013 20:23:18]

########## EOF - C:\AdwCleaner[R1].txt - [45529 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#4 Příspěvek od Rudy »

Spusťte znovu ADWCleaner a klikněte na >Delete< (smazat). Vložte nový log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#5 Příspěvek od miso25 »

# AdwCleaner v2.303 - Log vytvorený 12/06/2013 o 21:19:07
# Aktualizované 08/06/2013 Xplode
# Operaený systém : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Uživateľ : pc - PC-PC
# Spustený systém : Normálny
# Spustené z : D:\Downloads\adwcleaner.exe
# Voľba [Vymaza?]


***** [Služby] *****

Zastavené & vymazané : FunshionSvr
Zastavené & vymazané : PCSUService

***** [Súbory / Adresáre] *****

Súbor Vymazané : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\searchplugins\Conduit.xml
Vymazané pri reštarte : C:\Program Files (x86)\BitTorrentBar
Vymazané pri reštarte : C:\Program Files (x86)\Conduit
Vymazané pri reštarte : C:\Program Files (x86)\ConduitEngine
Vymazané pri reštarte : C:\Program Files (x86)\Hot_MP3
Vymazané pri reštarte : C:\Program Files (x86)\SimilarSites
Vymazané pri reštarte : C:\ProgramData\Trymedia
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\BitTorrentBar
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\Conduit
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\ConduitEngine
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\Hot_MP3
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\MyAshampoo
Vymazané pri reštarte : C:\Users\pc\AppData\LocalLow\PriceGong
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\Desktopicon
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\Conduit
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\ConduitCommon
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\CT2790392
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
Vymazané pri reštarte : C:\Users\pc\AppData\Roaming\SimilarSites

***** [Registre] *****

Hodnota Vymazané : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Vymazané : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Vymazané : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Vymazané : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Vymazané : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Vymazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Vymazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Vymazané : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Hodnota Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Hodnota Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Hodnota Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Hodnota Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}]
Kľúe Vymazané : HKCU\Software\APN PIP
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\BitTorrentBar
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\Conduit
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\conduitEngine
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\Hot_MP3
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\MyAshampoo
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\MyAshampoo\toolbar
Kľúe Vymazané : HKCU\Software\AppDataLow\Software\PriceGong
Kľúe Vymazané : HKCU\Software\AppDataLow\Toolbar
Kľúe Vymazané : HKCU\Software\Conduit
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BitTorrentBar Toolbar
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Hot_MP3 Toolbar
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyAshampoo Toolbar
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D382FE6-D448-41B2-A701-64DA06ACC6EC}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3FAF4281-AA13-4196-8CDD-BB4A89C01D04}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{685E2007-F722-4D48-BC42-5FAA692CF1B2}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7525BAEF-1A1A-40BA-9C47-09C91A8E37B8}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Vymazané : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Vymazané : HKCU\Software\PIP
Kľúe Vymazané : HKCU\Software\Softonic
Kľúe Vymazané : HKCU\Software\TENCENT
Kľúe Vymazané : HKCU\Software\YahooPartnerToolbar
Kľúe Vymazané : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Kľúe Vymazané : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Kľúe Vymazané : HKLM\Software\BitTorrentBar
Kľúe Vymazané : HKLM\SOFTWARE\Classes\Conduit.Engine
Kľúe Vymazané : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Kľúe Vymazané : HKLM\SOFTWARE\Classes\Toolbar.CT1066435
Kľúe Vymazané : HKLM\SOFTWARE\Classes\Toolbar.CT2475029
Kľúe Vymazané : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Kľúe Vymazané : HKLM\SOFTWARE\Classes\TypeLib\{CCA8F2AB-BE4E-41F0-A289-4D960CEA58EA}
Kľúe Vymazané : HKLM\Software\Conduit
Kľúe Vymazané : HKLM\Software\conduitEngine
Kľúe Vymazané : HKLM\Software\Hot_MP3
Kľúe Vymazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0D35EE00-A057-488B-A7C2-24C4713B2BC0}
Kľúe Vymazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A408D3B0-61A5-4D46-AE04-4D8A5E838AB2}
Kľúe Vymazané : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CA1412E1-B190-4E95-90E2-3D04B728699B}
Kľúe Vymazané : HKLM\Software\MyAshampoo
Kľúe Vymazané : HKLM\Software\MyAshampoo\toolbar
Kľúe Vymazané : HKLM\Software\PIP
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{0D35EE00-A057-488B-A7C2-24C4713B2BC0}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1D382FE6-D448-41B2-A701-64DA06ACC6EC}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3FAF4281-AA13-4196-8CDD-BB4A89C01D04}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{685E2007-F722-4D48-BC42-5FAA692CF1B2}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7525BAEF-1A1A-40BA-9C47-09C91A8E37B8}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A408D3B0-61A5-4D46-AE04-4D8A5E838AB2}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CA1412E1-B190-4E95-90E2-3D04B728699B}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{23F14776-18FF-405D-AA2C-90C5AE2F77A5}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E5D04B7-415D-4F0A-9855-B604128FED8C}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E09B09D-25AB-427A-A64C-24AAD112D693}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4DC8-84D1-F5D7BAF2DB0C}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ADBABBD-E1CA-4F11-BD01-73B0B6E4B5BA}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1E75A0E-4397-4BA8-BB50-E19FB66890F4}
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentBar Toolbar
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Kľúe Vymazané : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hot_MP3 Toolbar
Kľúe Vymazané : HKLM\SOFTWARE\Classes\Interface\{A36BCB13-778D-4A40-99C1-D686086D268F}

***** [Internetové prehliadaee] *****

-\\ Internet Explorer v9.0.8112.16490

[OK] Registre sú eisté.

-\\ Mozilla Firefox v21.0 (sk)

Súbor : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\prefs.js

C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\user.js ... Vymazané !

Vymazané : user_pref("CT2790392..clientLogIsEnabled", false);
Vymazané : user_pref("CT2790392..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Vymazané : user_pref("CT2790392..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Vymazané : user_pref("CT2790392.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Vymazané : user_pref("CT2790392.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Vymazané : user_pref("CT2790392.AppTrackingLastCheckTime", "Fri Aug 24 2012 14:00:48 GMT+0200");
Vymazané : user_pref("CT2790392.BrowserCompStateIsOpen_129633547190125290", true);
Vymazané : user_pref("CT2790392.BrowserCompStateIsOpen_130059329278017115", true);
Vymazané : user_pref("CT2790392.BrowserCompStateIsOpen_1359634298000", true);
Vymazané : user_pref("CT2790392.CTID", "CT2790392");
Vymazané : user_pref("CT2790392.CurrentServerDate", "12-6-2013");
Vymazané : user_pref("CT2790392.DialogsAlignMode", "LTR");
Vymazané : user_pref("CT2790392.DialogsGetterLastCheckTime", "Thu Jun 06 2013 21:54:55 GMT+0200");
Vymazané : user_pref("CT2790392.DownloadReferralCookieData", "");
Vymazané : user_pref("CT2790392.EMailNotifierPollDate", "Wed Jun 12 2013 20:57:43 GMT+0200");
Vymazané : user_pref("CT2790392.FeedLastCount129313977501788460", 500);
Vymazané : user_pref("CT2790392.FeedPollDate129313974171006416", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313975698350231", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313976370850190", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313976648818968", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313977444757117", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313980389131455", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313980655381977", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313980886163259", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313981234756535", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313983226631720", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedPollDate129313983607725691", "Wed Jun 12 2013 20:58:58 GMT+0200");
Vymazané : user_pref("CT2790392.FeedTTL129313974171006416", 10);
Vymazané : user_pref("CT2790392.FeedTTL129313975698350231", 5);
Vymazané : user_pref("CT2790392.FeedTTL129313977444757117", 15);
Vymazané : user_pref("CT2790392.FeedTTL129313980655381977", 5);
Vymazané : user_pref("CT2790392.FeedTTL129313981234756535", 5);
Vymazané : user_pref("CT2790392.FirstServerDate", "20-11-2010");
Vymazané : user_pref("CT2790392.FirstTime", true);
Vymazané : user_pref("CT2790392.FirstTimeFF3", true);
Vymazané : user_pref("CT2790392.FixPageNotFoundErrors", false);
Vymazané : user_pref("CT2790392.GroupingServerCheckInterval", 1440);
Vymazané : user_pref("CT2790392.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Vymazané : user_pref("CT2790392.HasUserGlobalKeys", true);
Vymazané : user_pref("CT2790392.HomePageProtectorEnabled", false);
Vymazané : user_pref("CT2790392.Initialize", true);
Vymazané : user_pref("CT2790392.InitializeCommonPrefs", true);
Vymazané : user_pref("CT2790392.InstallationAndCookieDataSentCount", 3);
Vymazané : user_pref("CT2790392.InstallationType", "UnknownIntegration");
Vymazané : user_pref("CT2790392.InstalledDate", "Sat Nov 20 2010 12:52:12 GMT+0100");
Vymazané : user_pref("CT2790392.IsAlertDBUpdated", true);
Vymazané : user_pref("CT2790392.IsGrouping", false);
Vymazané : user_pref("CT2790392.IsMulticommunity", false);
Vymazané : user_pref("CT2790392.IsOpenThankYouPage", true);
Vymazané : user_pref("CT2790392.IsOpenUninstallPage", false);
Vymazané : user_pref("CT2790392.LanguagePackLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Vymazané : user_pref("CT2790392.LanguagePackReloadIntervalMM", 1440);
Vymazané : user_pref("CT2790392.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Vymazané : user_pref("CT2790392.LastLogin_3.10.0.1", "Tue Apr 17 2012 17:57:38 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.12.0.7", "Tue Apr 24 2012 20:39:00 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.12.2.3", "Thu May 31 2012 01:11:38 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.13.0.6", "Tue Jul 17 2012 19:48:18 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.14.1.0", "Tue Aug 28 2012 16:51:07 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.15.1.0", "Wed Nov 07 2012 14:57:49 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.16.0.3", "Mon Mar 04 2013 19:42:35 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.18.0.7", "Wed Jun 12 2013 20:12:43 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.2.3.3", "Tue Mar 22 2011 16:08:11 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.3.3.2", "Thu Jun 23 2011 11:25:44 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.5.0.12", "Tue Aug 16 2011 23:07:54 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.6.0.10", "Fri Sep 23 2011 07:42:44 GMT+0200");
Vymazané : user_pref("CT2790392.LastLogin_3.7.0.6", "Wed Nov 09 2011 12:51:57 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.8.0.8", "Tue Dec 06 2011 13:06:03 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.8.1.0", "Wed Jan 11 2012 19:57:56 GMT+0100");
Vymazané : user_pref("CT2790392.LastLogin_3.9.0.3", "Thu Mar 08 2012 15:02:54 GMT+0100");
Vymazané : user_pref("CT2790392.LatestVersion", "3.18.0.7");
Vymazané : user_pref("CT2790392.Locale", "en");
Vymazané : user_pref("CT2790392.MCDetectTooltipHeight", "83");
Vymazané : user_pref("CT2790392.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Vymazané : user_pref("CT2790392.MCDetectTooltipWidth", "295");
Vymazané : user_pref("CT2790392.MyStuffEnabledAtInstallation", true);
Vymazané : user_pref("CT2790392.SHRINK_TOOLBAR", 1);
Vymazané : user_pref("CT2790392.SearchEngineBeforeUnload", "Google");
Vymazané : user_pref("CT2790392.SearchFromAddressBarIsInit", true);
Vymazané : user_pref("CT2790392.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT279[...]
Vymazané : user_pref("CT2790392.SearchInNewTabEnabled", true);
Vymazané : user_pref("CT2790392.SearchInNewTabIntervalMM", 1440);
Vymazané : user_pref("CT2790392.SearchInNewTabLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Vymazané : user_pref("CT2790392.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Vymazané : user_pref("CT2790392.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Vymazané : user_pref("CT2790392.SearchProtectorEnabled", false);
Vymazané : user_pref("CT2790392.SearchProtectorToolbarDisabled", false);
Vymazané : user_pref("CT2790392.ServiceMapLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Vymazané : user_pref("CT2790392.SettingsLastCheckTime", "Wed Jun 12 2013 20:58:57 GMT+0200");
Vymazané : user_pref("CT2790392.SettingsLastUpdate", "1371024743");
Vymazané : user_pref("CT2790392.ThirdPartyComponentsInterval", 504);
Vymazané : user_pref("CT2790392.ThirdPartyComponentsLastCheck", "Thu Jun 06 2013 02:02:43 GMT+0200");
Vymazané : user_pref("CT2790392.ThirdPartyComponentsLastUpdate", "1331805997");
Vymazané : user_pref("CT2790392.ToolbarShrinkedFromSetup", false);
Vymazané : user_pref("CT2790392.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2790392");
Vymazané : user_pref("CT2790392.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Vymazané : user_pref("CT2790392.UserID", "UN95743413213082986");
Vymazané : user_pref("CT2790392.ValidationData_Search", 2);
Vymazané : user_pref("CT2790392.ValidationData_Toolbar", 2);
Vymazané : user_pref("CT2790392.WeatherNetwork", "");
Vymazané : user_pref("CT2790392.WeatherPollDate", "Wed Jun 12 2013 20:58:57 GMT+0200");
Vymazané : user_pref("CT2790392.WeatherUnit", "C");
Vymazané : user_pref("CT2790392.alertChannelId", "1182482");
Vymazané : user_pref("CT2790392.appApproved.129309578575850709", true);
Vymazané : user_pref("CT2790392.backendstorage./9b+7e+x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e,x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e-x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e.:2z527", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e.x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e/x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e06cg5el8:", "6E6D6B716F6D75737071");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473717775737B797677242F4B4947[...]
Vymazané : user_pref("CT2790392.backendstorage./9b+7e0x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e1x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e2x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e3x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e4x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e5x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e6x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e7x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e8x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e9x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e:x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e;x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e<x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e=x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e>x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e?x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7e@x305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7eax305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
Vymazané : user_pref("CT2790392.backendstorage./9b+7ebx305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7ecx305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7edx305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b+7etx305", "2423");
Vymazané : user_pref("CT2790392.backendstorage./9b-0?3g>d", "3D3B6B3C414372437A70464678207C4A777B25214D7C242A25[...]
Vymazané : user_pref("CT2790392.backendstorage./9b-0?3g@6:5;", "");
Vymazané : user_pref("CT2790392.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
Vymazané : user_pref("CT2790392.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F292A212C393D44307832332[...]
Vymazané : user_pref("CT2790392.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
Vymazané : user_pref("CT2790392.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477A213F3E484F4E4D464[...]
Vymazané : user_pref("CT2790392.backendstorage./9b5ba==9cjag", "66706B3E71416D417A7143727679497A497B202252");
Vymazané : user_pref("CT2790392.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6A717370706D6E77777978");
Vymazané : user_pref("CT2790392.backendstorage./9b9643g3/9e", "6A");
Vymazané : user_pref("CT2790392.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
Vymazané : user_pref("CT2790392.backendstorage./9b<:222h64<", "393F352F3E");
Vymazané : user_pref("CT2790392.backendstorage./9b<:222h64<l8daj", "6D70706F7674737975772A7973727C7C757B7A");
Vymazané : user_pref("CT2790392.backendstorage./9b=+03eh8h8j?:", "4443");
Vymazané : user_pref("CT2790392.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
Vymazané : user_pref("CT2790392.backendstorage./9b?b0d:8aj62<h", "6D");
Vymazané : user_pref("CT2790392.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
Vymazané : user_pref("CT2790392.backendstorage.cb", "31");
Vymazané : user_pref("CT2790392.backendstorage.cb_experience_000", "323532");
Vymazané : user_pref("CT2790392.backendstorage.cb_firstuse0100", "31");
Vymazané : user_pref("CT2790392.backendstorage.cb_user_id_000", "43423938373035313433353934395F46697265666F78")[...]
Vymazané : user_pref("CT2790392.backendstorage.cb_user_id_002", "43423834353432323939313332335F46697265666F78")[...]
Vymazané : user_pref("CT2790392.backendstorage.cbcountry_000", "4E4C");
Vymazané : user_pref("CT2790392.backendstorage.cbcountry_001", "534B");
Vymazané : user_pref("CT2790392.backendstorage.cbfirsttime", "5765642053657020323820323031312031313A30363A31302[...]
Vymazané : user_pref("CT2790392.backendstorage.cbopenmamsettings", "30");
Vymazané : user_pref("CT2790392.backendstorage.facebook_mode", "32");
Vymazané : user_pref("CT2790392.backendstorage.facebook_user_locale", "656E");
Vymazané : user_pref("CT2790392.backendstorage.first_use_pending", "66616C7365");
Vymazané : user_pref("CT2790392.backendstorage.for_aoi", "31333033313136323234");
Vymazané : user_pref("CT2790392.backendstorage.for_ccid", "4272617469736C617661");
Vymazané : user_pref("CT2790392.backendstorage.for_cdtr", "31333034363835323139");
Vymazané : user_pref("CT2790392.backendstorage.for_cdtr6", "31333135353538323737");
Vymazané : user_pref("CT2790392.backendstorage.for_cid", "534B");
Vymazané : user_pref("CT2790392.backendstorage.for_ip", "37382E39392E35312E313735");
Vymazané : user_pref("CT2790392.backendstorage.for_lcut", "31333731303435393930");
Vymazané : user_pref("CT2790392.backendstorage.for_rid", "3032");
Vymazané : user_pref("CT2790392.backendstorage.for_zoneid", "37383136");
Vymazané : user_pref("CT2790392.backendstorage.hxxp://conduit_priceblink_com/conduit.uid", "34666532383936392D3[...]
Vymazané : user_pref("CT2790392.backendstorage.hxxp://staging_priceblink_com/conduit.uid", "39643833613534392D3[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_appsdata", "7B2261707073223A5B7B226964223A225072696365476[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_appsdefaultenabled", "6E756C6C");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_appstate_couponbuddy", "6F6E");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_appstate_pricegong", "6F6E");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_appstatereporttime", "31333731303630373634393134");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_configuration", "7B22636F6E66696775726174696F6E223A5B7B22[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_currentversion", "312E382E302E34");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_first_time", "31");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_lastlogintime", "31333731303630373635313938");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_localization", "7B22676164676574436F6E74656E74506F6C69637[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.0.4", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.3.1", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.3.2", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.4.4.6", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.6.0.1", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_settings1.8.0.4", "7B22537461747573223A227375636365656465[...]
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_showclosebutton", "74727565");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_showwelcomegadget", "66616C7365");
Vymazané : user_pref("CT2790392.backendstorage.mam_gk_userid", "32346662623633342D303138372D346332332D393265612[...]
Vymazané : user_pref("CT2790392.backendstorage.pairingkey", "33314444343241434438303642363539364345323037354336[...]
Vymazané : user_pref("CT2790392.backendstorage.pg_enable", "74727565");
Vymazané : user_pref("CT2790392.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Vymazané : user_pref("CT2790392.backendstorage.searchappstate", "33");
Vymazané : user_pref("CT2790392.backendstorage.searchapptracking", "31");
Vymazané : user_pref("CT2790392.backendstorage.undefined", "4672692046656220303320323031322031343A31393A3235204[...]
Vymazané : user_pref("CT2790392.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E736B2F75726C3[...]
Vymazané : user_pref("CT2790392.backendstorage.url_history0001", "687474703A2F2F7777772E637366642E637A2F757A697[...]
Vymazané : user_pref("CT2790392.backendstorage.uttorrents", "7B226275696C64223A32383730362C226C6162656C223A5B5D[...]
Vymazané : user_pref("CT2790392.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Vymazané : user_pref("CT2790392.globalFirstTimeInfoLastCheckTime", "Sun Jun 09 2013 00:36:18 GMT+0200");
Vymazané : user_pref("CT2790392.homepageProtectorEnableByLogin", true);
Vymazané : user_pref("CT2790392.initDone", true);
Vymazané : user_pref("CT2790392.isAppTrackingManagerOn", false);
Vymazané : user_pref("CT2790392.myStuffEnabled", true);
Vymazané : user_pref("CT2790392.myStuffPublihserMinWidth", 400);
Vymazané : user_pref("CT2790392.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Vymazané : user_pref("CT2790392.myStuffServiceIntervalMM", 1440);
Vymazané : user_pref("CT2790392.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Vymazané : user_pref("CT2790392.oldAppsList", "129298377186075601,129298377186388102,1000234,129791371079091292[...]
Vymazané : user_pref("CT2790392.revertSettingsEnabled", true);
Vymazané : user_pref("CT2790392.searchProtectorDialogDelayInSec", 10);
Vymazané : user_pref("CT2790392.searchProtectorEnableByLogin", true);
Vymazané : user_pref("CT2790392.testingCtid", "");
Vymazané : user_pref("CT2790392.toolbarAppMetaDataLastCheckTime", "Wed Jun 12 2013 16:06:27 GMT+0200");
Vymazané : user_pref("CT2790392.toolbarContextMenuLastCheckTime", "Thu May 30 2013 00:22:04 GMT+0200");
Vymazané : user_pref("CT2790392.usagesFlag", 2);
Vymazané : user_pref("CommunityToolbar.CantToolbarBeEngineOwner", "");
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=1182482&fid=1178159", "\"0\[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/?aid=909619&fid=905414", "\"0\""[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1182482/1178159/SK", "\"0\"[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/868510/864310/SK", "\"0\"")[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/SK", "\"0\"")[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2475029", [...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2790392", [...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.engine.conduit-services.com/apps/TranslatedApps.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.3[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.16[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2475029",[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2790392",[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"63433363123173[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=1/11/20[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=11/8/20[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/21/2[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/27/2[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=12/30/2[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/17/20[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=2/22/20[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=3/13/20[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2790392&octid=[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/?ctid=CT2790392&octid=CT[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2475029/CT2475029[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/equaliz[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/minimiz[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/play.gi[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/stop.gi[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Cornflower/vol.gif[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"4f3[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/1344951.xml", "\"7e980a8f68c25685ee06[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/16887175.xml", "\"49e64dfe80b4e799239[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/17151925.xml", "\"4c29e33e2f421035216[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/20536157.xml", "\"4a2d9edd9129fe92ff8[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/30261067.xml", "\"b62a911cf815e6dc217[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/34655603.xml", "\"2616c8c0e421179da1e[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/759251.xml", "\"dcb0590fabf0766b00f63[...]
Vymazané : user_pref("CommunityToolbar.ETag.hxxp://twitter.com/users/show/816653.xml", "\"c10137f6c5f383ff1d244[...]
Vymazané : user_pref("CommunityToolbar.EngineOwner", "");
Vymazané : user_pref("CommunityToolbar.EngineOwnerGuid", "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}");
Vymazané : user_pref("CommunityToolbar.EngineOwnerToolbarId", "bittorrentbar");
Vymazané : user_pref("CommunityToolbar.IsEngineShown", true);
Vymazané : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Vymazané : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\pc\\AppData\\Roaming\\Mozilla\\Fire[...]
Vymazané : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.18.0.7");
Vymazané : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://cdn.triplegames.com/shared/apps/gamearcade/ar[...]
Vymazané : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://facebook.conduitapps.com/v3.13/gadget.html", [...]
Vymazané : user_pref("CommunityToolbar.MiniIPageGadgetSize.hxxp://youtube.conduitapps.com/v115/gadget.php?appMo[...]
Vymazané : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2790392");
Vymazané : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}");
Vymazané : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "bittorrentbar");
Vymazané : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://slirsredirect.search.aol.com/slir[...]
Vymazané : user_pref("CommunityToolbar.ToolbarsList", "CT2790392");
Vymazané : user_pref("CommunityToolbar.ToolbarsList2", "ConduitEngine,CT2790392");
Vymazané : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Wed Mar 23 2011 15:26:49 GMT+01[...]
Vymazané : user_pref("CommunityToolbar.alert.alertEnabled", true);
Vymazané : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Vymazané : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu Jun 23 2011 11:25:52 GMT+0200");
Vymazané : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Vymazané : user_pref("CommunityToolbar.alert.firstTimeAlertShown", true);
Vymazané : user_pref("CommunityToolbar.alert.locale", "en");
Vymazané : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Vymazané : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu Jun 23 2011 11:25:44 GMT+0200");
Vymazané : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Vymazané : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Vymazané : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Vymazané : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Vymazané : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Vymazané : user_pref("CommunityToolbar.alert.userId", "7431bc77-5dd7-4744-b15f-eb6ca9a6c58b");
Vymazané : user_pref("CommunityToolbar.facebook.sessionKey", "2.AQC4WwHr2qNSGXaO.86400.1322913600.0-10000104862[...]
Vymazané : user_pref("CommunityToolbar.facebook.sessionSecret", "6_HlVxYU1LwJnAKOYzlEEQ__");
Vymazané : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Tue Apr 17 2012 17:57:37 GMT+0200");
Vymazané : user_pref("CommunityToolbar.facebook.userId", "100001048620214");
Vymazané : user_pref("CommunityToolbar.globalUserId", "be2a8d9d-c9fd-43d9-99e4-cd42a5952dc6");
Vymazané : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Vymazané : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Vymazané : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2475029");
Vymazané : user_pref("CommunityToolbar.killedEngine", true);
Vymazané : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jun 05 2013 21:09:3[...]
Vymazané : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Vymazané : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Vymazané : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Jun 12 2013 16:06:35 GMT+020[...]
Vymazané : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Vymazané : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Vymazané : user_pref("CommunityToolbar.notifications.locale", "en");
Vymazané : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Vymazané : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jun 12 2013 16:06:28 GMT+0200");
Vymazané : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Vymazané : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Vymazané : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Vymazané : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Vymazané : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Vymazané : user_pref("CommunityToolbar.notifications.userId", "55c50faf-1e33-4971-91fc-cf102e6a9622");
Vymazané : user_pref("CommunityToolbar.twitter.user_1344951.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200"[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_16887175.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_17151925.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_20536157.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_30261067.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_34655603.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_759251.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200")[...]
Vymazané : user_pref("CommunityToolbar.twitter.user_816653.LastCheckTime", "Mon Apr 04 2011 19:06:52 GMT+0200")[...]
Vymazané : user_pref("CommunityToolbar.undefined", "");
Vymazané : user_pref("browser.search.defaultenginename", "Winamp Search");
Vymazané : user_pref("browser.search.defaultthis.engineName", "MyAshampoo Customized Web Search");
Vymazané : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&Sea[...]
Vymazané : user_pref("keyword.URL", "hxxp://slirsredirect.search.aol.com/slirs_hxxp/sredir?sredir=2685&invocati[...]
Vymazané : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");

-\\ Google Chrome v27.0.1453.110

Súbor : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Súbor je eistý.

-\\ Chromium v directory_upgrade: true
}

Súbor : C:\Users\pc\AppData\Local\Chromium\User Data\Default\Preferences

[OK] Súbor je eistý.

*************************

AdwCleaner[R1].txt - [45593 octets] - [12/06/2013 20:23:18]
AdwCleaner[S1].txt - [44072 octets] - [12/06/2013 21:19:07]

########## EOF - C:\AdwCleaner[S1].txt - [44133 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#6 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#7 Příspěvek od miso25 »

aha pardon # AdwCleaner v2.303 - Log vytvorený 12/06/2013 o 21:38:00
# Aktualizované 08/06/2013 Xplode
# Operaený systém : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Uživateľ : pc - PC-PC
# Spustený systém : Normálny
# Spustené z : D:\Downloads\adwcleaner.exe
# Voľba [Prehľada?]


***** [Služby] *****


***** [Súbory / Adresáre] *****

Adresár Nájdené : C:\Program Files (x86)\Conduit
Adresár Nájdené : C:\Program Files (x86)\ConduitEngine
Adresár Nájdené : C:\Program Files (x86)\SimilarSites

***** [Registre] *****


***** [Internetové prehliadaee] *****

-\\ Internet Explorer v9.0.8112.16490

[OK] Registre sú eisté.

-\\ Mozilla Firefox v21.0 (sk)

Súbor : C:\Users\pc\AppData\Roaming\Mozilla\Firefox\Profiles\0t6j0k41.default\prefs.js

[OK] Súbor je eistý.

-\\ Google Chrome v27.0.1453.110

Súbor : C:\Users\pc\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Súbor je eistý.

-\\ Chromium v directory_upgrade: true
}

Súbor : C:\Users\pc\AppData\Local\Chromium\User Data\Default\Preferences

[OK] Súbor je eistý.

*************************

AdwCleaner[R2].txt - [1128 octets] - [12/06/2013 21:38:00]

########## EOF - C:\AdwCleaner[R2].txt - [1188 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#8 Příspěvek od Rudy »

RSIT je to, co jste dával ve svém 1. postu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#9 Příspěvek od miso25 »

ale mne to dal len toto co som sem daval teraz nic ine.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#10 Příspěvek od Rudy »

Ano. Toto je log z nového skenu ADW. Potřebuji log z: http://forum.viry.cz/viewtopic.php?f=24&t=130784 na dočištění.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#11 Příspěvek od miso25 »

Logfile of random's system information tool 1.09 (written by random/random)
Run by pc at 2013-06-12 22:47:09
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 38 GB (21%) free of 180 GB
Total RAM: 6142 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:47:10, on 12. 6. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16490)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\BitTorrent\bittorrent.exe
C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Program Files\trend micro\pc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Keyword Search - {31A0D938-3055-46BA-8919-59E44E0D7E51} - C:\Program Files (x86)\Keyword Search\torangcomz.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: TopSpaceHelper - {C8625893-2C0F-4484-8C18-52B00D5A8BB9} - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared files\brs.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [WJNews_2013511] "C:\Program Files\Wuji\2013511\WJPap.exe" -mini
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [KeywordSearchUpdater] C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Keyboard Inf.] C:\Users\pc\AppData\Roaming\runic games\msdn.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3719279243-3044573747-122376168-1006\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: SimilarWeb - {5D06ED6E-DA78-4486-A246-B131A2C39807} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Baidu Updater (BaiduUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate1cac0be77e89afe) (gupdate1cac0be77e89afe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9169 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k rpcss
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
taskeng.exe {11F7348F-1916-4E70-AC8D-5F6CCCEE41FB}
C:\Windows\Explorer.EXE
taskeng.exe {783FDF04-0DF9-4492-92B0-D9E7D166AA97}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\RAVCpl64.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Windows\ehome\ehtray.exe"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Users\pc\AppData\Roaming\runic games\msdn.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\brs.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\system32\conime.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\BitTorrent\bittorrent.exe" /NOINSTALL
"C:\Program Files (x86)\SpeedFan\speedfan.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"D:\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31A0D938-3055-46BA-8919-59E44E0D7E51}]
Keyword Search - C:\Program Files (x86)\Keyword Search\torangcomz.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-04 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8625893-2C0F-4484-8C18-52B00D5A8BB9}]
TopSpaceHelper Class - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-04 171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{74198672-5F7D-4FE9-A611-4AC1D5A66A15} - SimilarWeb - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll [2013-01-28 320888]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2008-07-24 6452256]
"Skytel"=C:\Windows\Skytel.exe [2008-07-24 1833504]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2013-06-07 1641896]
"KeywordSearchUpdater"=C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []
"Keyboard Inf."=C:\Users\pc\AppData\Roaming\runic games\msdn.exe [2013-06-09 5178368]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"RemoteControl9"=C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-07-06 87336]
"PDVD9LanguageShortcut"=C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [2009-04-27 50472]
"BDRegion"=C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [2009-11-19 75048]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
"WJNews_2013511"=C:\Program Files\Wuji\2013511\WJPap.exe -mini []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes3\deskscapes.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\BitTorrent\bittorrent.exe"="C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-06-12 22:45:21 ----D---- C:\rsit
2013-06-12 21:19:15 ----A---- C:\Windows\DeleteOnReboot.bat
2013-06-12 19:14:33 ----D---- C:\Program Files\trend micro
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-06-12 17:59:21 ----A---- C:\Windows\system32\mshtmled.dll
2013-06-12 17:59:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-06-12 17:59:20 ----A---- C:\Windows\system32\ieui.dll
2013-06-12 17:59:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-06-12 17:59:19 ----A---- C:\Windows\system32\jsproxy.dll
2013-06-12 17:59:19 ----A---- C:\Windows\system32\ieUnatt.exe
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\url.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\url.dll
2013-06-12 17:59:17 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\vbscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\jscript.dll
2013-06-12 17:59:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-06-12 17:59:15 ----A---- C:\Windows\system32\iertutil.dll
2013-06-12 17:59:14 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\ieframe.dll
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\certutil.exe
2013-06-12 17:55:05 ----A---- C:\Windows\system32\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\system32\certutil.exe
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\certenc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\certenc.dll
2013-06-12 17:53:52 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2013-06-12 17:53:52 ----A---- C:\Windows\system32\cryptdlg.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\printcom.dll
2013-06-12 17:53:51 ----A---- C:\Windows\system32\win32spl.dll
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)\SpeedFan
2013-05-18 02:01:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-17 22:41:01 ----D---- C:\Users\pc\AppData\Roaming\Arrowhead
2013-05-17 22:40:57 ----D---- C:\Windows\9530AE42DAE146199594B23487285D17.TMP
2013-05-16 00:11:23 ----A---- C:\Windows\system32\win32k.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\cdd.dll

======List of files/folders modified in the last 1 month======

2013-06-12 22:47:06 ----D---- C:\Windows\Temp
2013-06-12 22:46:33 ----D---- C:\Users\pc\AppData\Roaming\BitTorrent
2013-06-12 22:31:49 ----D---- C:\Program Files (x86)\Steam
2013-06-12 21:27:22 ----D---- C:\Windows\System32
2013-06-12 21:27:22 ----D---- C:\Windows\inf
2013-06-12 21:27:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-06-12 21:21:18 ----HD---- C:\ProgramData
2013-06-12 21:19:15 ----D---- C:\Windows
2013-06-12 20:10:49 ----RSD---- C:\Windows\assembly
2013-06-12 20:10:49 ----D---- C:\Windows\Microsoft.NET
2013-06-12 19:14:33 ----RD---- C:\Program Files
2013-06-12 19:05:25 ----SHD---- C:\System Volume Information
2013-06-12 18:55:49 ----D---- C:\Windows\rescache
2013-06-12 18:47:35 ----SHD---- C:\Windows\Installer
2013-06-12 18:38:16 ----D---- C:\Windows\Prefetch
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\en-US
2013-06-12 18:35:08 ----D---- C:\Windows\SysWOW64
2013-06-12 18:35:08 ----D---- C:\Windows\system32\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\system32\en-US
2013-06-12 18:35:07 ----D---- C:\Windows\system32\drivers
2013-06-12 18:35:06 ----D---- C:\Windows\SYSWOW64\migration
2013-06-12 18:35:06 ----D---- C:\Windows\system32\migration
2013-06-12 18:35:06 ----D---- C:\Program Files (x86)\Internet Explorer
2013-06-12 18:35:05 ----D---- C:\Program Files\Internet Explorer
2013-06-12 18:26:26 ----D---- C:\ProgramData\Microsoft Help
2013-06-12 18:25:50 ----D---- C:\Windows\winsxs
2013-06-12 18:22:52 ----D---- C:\Windows\Debug
2013-06-12 18:22:51 ----A---- C:\Windows\system32\mrt.exe
2013-06-12 18:22:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-06-12 17:59:50 ----D---- C:\Windows\system32\catroot
2013-06-12 17:59:47 ----D---- C:\Windows\system32\catroot2
2013-06-12 16:50:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-06-11 20:34:18 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-06-11 20:33:20 ----SD---- C:\ProgramData\Microsoft
2013-06-11 20:33:20 ----D---- C:\Windows\Tasks
2013-06-11 14:01:33 ----D---- C:\Users\pc\AppData\Roaming\vlc
2013-06-09 01:39:23 ----D---- C:\Users\pc\AppData\Roaming\runic games
2013-06-09 01:17:48 ----D---- C:\Users\pc\AppData\Roaming\NationRed
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)
2013-05-18 07:17:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2008-11-04 98144]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-31 834544]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/03/19 01:30:04]; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-02-28 146928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-08-11 72216]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2008-07-24 1488032]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-08-11 11552]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-03-15 11048736]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2009-03-17 196096]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 87040]
S1 archlp;archlp; SysWOW64\drivers\archlp.sys []
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys []
S2 tandpl;tandpl; C:\Windows\System32\drivers\tandpl.sys []
S3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [2012-05-30 28320]
S3 asu1fe3n;asu1fe3n; C:\Windows\system32\drivers\asu1fe3n.sys []
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 cpuz135;cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 6144]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-04-22 12744]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-06-05 24104]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 11008]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 7936]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS_64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2009-05-08 602624]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 115240]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 19496]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 158760]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 137256]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 34344]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 136744]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 151592]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-04-11 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 46592]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 198656]
S3 X6va005;X6va005; \??\C:\Users\pc\AppData\Local\Temp\005656F.tmp []
S3 X6va006;X6va006; \??\C:\Users\pc\AppData\Local\Temp\006721B.tmp []
S3 xnacc;XBOX 360 Controller For Windows Driver Service; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 903168]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-04-08 68992]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 8704]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 438328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 27648]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-03-15 877856]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-15 1266464]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-07 543656]
S2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate1cac0be77e89afe;Služba Google Update (gupdate1cac0be77e89afe); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12 256904]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 BaiduUpdater;Baidu Updater; C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe []
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-08-15 130976]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-18 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#12 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Program Files\Wuji
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\9530AE42DAE146199594B23487285D17.TMP
C:\Users\pc\AppData\Local\Temp\005656F.tmp
C:\Users\pc\AppData\Local\Temp\006721B.tmp

:reg
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"WJNews_2013511"=-

:services
X6va005
X6va006

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#13 Příspěvek od miso25 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by pc at 2013-06-13 18:27:10
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 39 GB (22%) free of 180 GB
Total RAM: 6142 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:27:12, on 13. 6. 2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16490)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Program Files\trend micro\pc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Keyword Search - {31A0D938-3055-46BA-8919-59E44E0D7E51} - C:\Program Files (x86)\Keyword Search\torangcomz.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: TopSpaceHelper - {C8625893-2C0F-4484-8C18-52B00D5A8BB9} - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: SimilarWeb - {74198672-5F7D-4FE9-A611-4AC1D5A66A15} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared files\brs.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [KeywordSearchUpdater] C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Keyboard Inf.] C:\Users\pc\AppData\Roaming\runic games\msdn.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3719279243-3044573747-122376168-1006\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: SimilarWeb - {5D06ED6E-DA78-4486-A246-B131A2C39807} - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Baidu Updater (BaiduUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate1cac0be77e89afe) (gupdate1cac0be77e89afe) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9071 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k rpcss
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Windows\system32\Dwm.exe"
taskeng.exe {79B29C06-C452-49A1-AC05-32D3EF0129EC}
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
taskeng.exe {F16793C5-1E1E-4B77-B0DB-4DB89252564F}
"C:\Windows\RAVCpl64.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Windows\ehome\ehtray.exe"
C:\Windows\ehome\ehmsas.exe -Embedding
"C:\Users\pc\AppData\Roaming\runic games\msdn.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
"C:\Program Files (x86)\CyberLink\Shared Files\brs.exe"
"C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
wmiadap.exe /F /T /R
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4228.1064f700.1598009091 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" - 4228 "\\.\pipe\gecko-crash-server-pipe.4228" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe" --proxy-stub-channel=Flash4612.6C1BBDE0.13148 --host-broker-channel=Flash4612.6C1BBDE0.29454 --host-pid=4612 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe" --channel=4652.006DF478.876148904 --proxy-stub-channel=Flash4612.6C1BBDE0.13148 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll" --host-npapi-version=27 --type=renderer
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"D:\Downloads\RSITx64(1).exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31A0D938-3055-46BA-8919-59E44E0D7E51}]
Keyword Search - C:\Program Files (x86)\Keyword Search\torangcomz.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-04 462752]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C8625893-2C0F-4484-8C18-52B00D5A8BB9}]
TopSpaceHelper Class - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-04 171424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{74198672-5F7D-4FE9-A611-4AC1D5A66A15} - SimilarWeb - C:\Program Files (x86)\SimilarWeb\SimilarWeb.dll [2013-01-28 320888]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2008-07-24 6452256]
"Skytel"=C:\Windows\Skytel.exe [2008-07-24 1833504]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe []
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2013-01-27 1281512]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2013-06-07 1641896]
"KeywordSearchUpdater"=C:\Program Files (x86)\Keyword Search\KeywordSearchUpdater.exe []
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 138240]
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []
"Keyboard Inf."=C:\Users\pc\AppData\Roaming\runic games\msdn.exe [2013-06-09 5178368]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2007-03-20 36864]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"RemoteControl9"=C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-07-06 87336]
"PDVD9LanguageShortcut"=C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [2009-04-27 50472]
"BDRegion"=C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [2009-11-19 75048]
"NBKeyScan"=C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe []
"DivXUpdate"=C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21 1230704]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes3\deskscapes.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\BitTorrent\bittorrent.exe"="C:\Program Files (x86)\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2013-06-12 22:45:21 ----D---- C:\rsit
2013-06-12 21:19:15 ----A---- C:\Windows\DeleteOnReboot.bat
2013-06-12 19:14:33 ----D---- C:\Program Files\trend micro
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-06-12 17:59:21 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-06-12 17:59:21 ----A---- C:\Windows\system32\mshtmled.dll
2013-06-12 17:59:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-06-12 17:59:20 ----A---- C:\Windows\system32\ieui.dll
2013-06-12 17:59:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-06-12 17:59:19 ----A---- C:\Windows\system32\jsproxy.dll
2013-06-12 17:59:19 ----A---- C:\Windows\system32\ieUnatt.exe
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\url.dll
2013-06-12 17:59:18 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\wininet.dll
2013-06-12 17:59:18 ----A---- C:\Windows\system32\url.dll
2013-06-12 17:59:17 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\urlmon.dll
2013-06-12 17:59:17 ----A---- C:\Windows\system32\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-06-12 17:59:16 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\vbscript.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\msfeeds.dll
2013-06-12 17:59:16 ----A---- C:\Windows\system32\jscript.dll
2013-06-12 17:59:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-06-12 17:59:15 ----A---- C:\Windows\system32\iertutil.dll
2013-06-12 17:59:14 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\mshtml.dll
2013-06-12 17:59:11 ----A---- C:\Windows\system32\ieframe.dll
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2013-06-12 17:57:23 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\SYSWOW64\certutil.exe
2013-06-12 17:55:05 ----A---- C:\Windows\system32\crypt32.dll
2013-06-12 17:55:05 ----A---- C:\Windows\system32\certutil.exe
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\SYSWOW64\certenc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptsvc.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\cryptnet.dll
2013-06-12 17:55:04 ----A---- C:\Windows\system32\certenc.dll
2013-06-12 17:53:52 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2013-06-12 17:53:52 ----A---- C:\Windows\system32\cryptdlg.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-06-12 17:53:51 ----A---- C:\Windows\SYSWOW64\printcom.dll
2013-06-12 17:53:51 ----A---- C:\Windows\system32\win32spl.dll
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)\SpeedFan
2013-05-18 02:01:00 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-05-17 22:41:01 ----D---- C:\Users\pc\AppData\Roaming\Arrowhead
2013-05-16 00:11:23 ----A---- C:\Windows\system32\win32k.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-05-16 00:11:23 ----A---- C:\Windows\system32\cdd.dll

======List of files/folders modified in the last 1 months======

2013-06-13 18:27:09 ----D---- C:\Windows\Temp
2013-06-13 18:27:09 ----D---- C:\Windows\Prefetch
2013-06-13 18:21:14 ----D---- C:\Program Files (x86)\Steam
2013-06-13 18:19:33 ----D---- C:\Windows\SysWOW64
2013-06-13 18:19:33 ----D---- C:\Windows
2013-06-13 18:18:45 ----D---- C:\Windows\Tasks
2013-06-13 18:16:40 ----D---- C:\Users\pc\AppData\Roaming\BitTorrent
2013-06-13 15:07:40 ----D---- C:\Users\pc\AppData\Roaming\vlc
2013-06-12 21:27:22 ----D---- C:\Windows\System32
2013-06-12 21:27:22 ----D---- C:\Windows\inf
2013-06-12 21:27:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-06-12 21:21:18 ----HD---- C:\ProgramData
2013-06-12 20:10:49 ----RSD---- C:\Windows\assembly
2013-06-12 20:10:49 ----D---- C:\Windows\Microsoft.NET
2013-06-12 19:14:33 ----RD---- C:\Program Files
2013-06-12 19:05:25 ----SHD---- C:\System Volume Information
2013-06-12 18:55:49 ----D---- C:\Windows\rescache
2013-06-12 18:47:35 ----SHD---- C:\Windows\Installer
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\SYSWOW64\en-US
2013-06-12 18:35:08 ----D---- C:\Windows\system32\sk-SK
2013-06-12 18:35:08 ----D---- C:\Windows\system32\en-US
2013-06-12 18:35:07 ----D---- C:\Windows\system32\drivers
2013-06-12 18:35:06 ----D---- C:\Windows\SYSWOW64\migration
2013-06-12 18:35:06 ----D---- C:\Windows\system32\migration
2013-06-12 18:35:06 ----D---- C:\Program Files (x86)\Internet Explorer
2013-06-12 18:35:05 ----D---- C:\Program Files\Internet Explorer
2013-06-12 18:26:26 ----D---- C:\ProgramData\Microsoft Help
2013-06-12 18:25:50 ----D---- C:\Windows\winsxs
2013-06-12 18:22:52 ----D---- C:\Windows\Debug
2013-06-12 18:22:51 ----A---- C:\Windows\system32\mrt.exe
2013-06-12 18:22:22 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-06-12 17:59:50 ----D---- C:\Windows\system32\catroot
2013-06-12 17:59:47 ----D---- C:\Windows\system32\catroot2
2013-06-12 16:50:20 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-06-11 20:34:18 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-06-11 20:33:20 ----SD---- C:\ProgramData\Microsoft
2013-06-09 01:39:23 ----D---- C:\Users\pc\AppData\Roaming\runic games
2013-06-09 01:17:48 ----D---- C:\Users\pc\AppData\Roaming\NationRed
2013-05-19 04:20:57 ----D---- C:\Program Files (x86)
2013-05-18 07:17:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2008-11-04 98144]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-01-20 230320]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 17720]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-01-31 834544]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/03/19 01:30:04]; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [2009-02-28 146928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-08-11 72216]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-01-20 130008]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2008-07-24 1488032]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-08-11 11552]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-03-15 11048736]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2009-03-17 196096]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 87040]
S1 archlp;archlp; SysWOW64\drivers\archlp.sys []
S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys []
S2 tandpl;tandpl; C:\Windows\System32\drivers\tandpl.sys []
S3 AIDA64Driver;FinalWire AIDA64 Kernel Driver; \??\C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [2012-05-30 28320]
S3 angqu7al;angqu7al; C:\Windows\system32\drivers\angqu7al.sys []
S3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 cpuz135;cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x64.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 6144]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 ENTECH64;ENTECH64; \??\C:\Windows\system32\DRIVERS\ENTECH64.sys [2008-04-22 12744]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-06-05 24104]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 11008]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 7936]
S3 nmwcdcx64;Nokia USB Generic; C:\Windows\system32\drivers\ccdcmbox64.sys [2008-05-02 23552]
S3 nmwcdx64;Nokia USB Phone Parent; C:\Windows\system32\drivers\ccdcmbx64.sys [2008-05-02 18432]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS_64.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2009-05-08 602624]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 115240]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 19496]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 158760]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 137256]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 34344]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 136744]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 151592]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2010-03-15 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2010-03-15 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2010-03-15 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2010-03-15 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2010-03-15 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2010-03-15 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2010-03-15 158320]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2008-05-02 8704]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2009-04-11 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltx64j.sys [2008-05-02 8704]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 46592]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 198656]
S3 xnacc;XBOX 360 Controller For Windows Driver Service; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 903168]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-04-08 68992]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 8704]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 438328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 27648]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-01-27 22056]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-03-15 877856]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-15 1266464]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-01-27 379360]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-07 543656]
S2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate1cac0be77e89afe;Služba Google Update (gupdate1cac0be77e89afe); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12 256904]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 BaiduUpdater;Baidu Updater; C:\Program Files (x86)\Baidu\BaiduUpdate\bdupdate.exe []
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-08-15 130976]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-03-11 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-18 117144]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-21 19968]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2010-05-25 613888]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 TunngleService;TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2011-12-12 751464]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119526
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosim o kontrolu logu,asi mam virus.

#14 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\pc.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=29065018_246_hao_pg
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Keyword Search - {31A0D938-3055-46BA-8919-59E44E0D7E51} - C:\Program Files (x86)\Keyword Search\torangcomz.dll (file missing)
O2 - BHO: TopSpaceHelper - {C8625893-2C0F-4484-8C18-52B00D5A8BB9} - C:\Program Files (x86)\TopSpace\bin\TopSpaceHelper.dll (file missing)
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

miso25
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 12 čer 2013 17:59

Re: Prosim o kontrolu logu,asi mam virus.

#15 Příspěvek od miso25 »

takze to by malo byt vsetko alebo bude treba este nieco ?

Odpovědět