Stránka 1 z 1

Kontrola logu- zasekávání  Vyřešeno

Napsal: 07 úno 2012 13:36
od mEEEgy
Ahoj, dostal se mi do ruky sestry notebook, stáhla si kde jakou serepetičku, seká se jí to(sestra chce jen zachovat ICQ a Skype) prosím o kontrolu logu a říct co dál. Dík.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:36:15, on 7.2.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19170)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Replay Media Catcher\FLVSrvc.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbrmon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\ProgramData\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Xfire\Xfire.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://puvodni.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\100402935\ICQToolBar.dll
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
R3 - URLSearchHook: (no name) - {339a0dff-d9af-439b-92bc-636220fb3dae} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Toolbar BHO - {55cde9e7-696c-47c4-8e21-7210b8aeb103} - C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbar.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\100402935\ICQToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O3 - Toolbar: SmileyCentral - {d3ca5551-fc2e-4d09-8ece-263607acf9fc} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ask and Record FLV Service] "C:\Program Files\Replay Media Catcher\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [SmileyCentralIE_1w Browser Plugin Loader] C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbrmon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKCU\..\Run: [Badoo Desktop] C:\ProgramData\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Download Video by Free YouTuBe Utility - C:\Program Files\Free YouTuBe Utility\IEydown.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Služba Google Update (gupdate1cafb7e4917c4d0) (gupdate1cafb7e4917c4d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmileyCentral Service (SmileyCentralIE_1wService) - SmileyCentral - C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbarsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: WTGService - Unknown owner - C:\Program Files\Verbindungsassistent\wtgservice.exe

--
End of file - 12291 bytes

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 14:24
od jaro3
Odinstaluj:
ICQToolBar
DVDVideoSoftTB Toolbar
Ask Toolbar


Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\100402935\ICQToolBar.dll
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
R3 - URLSearchHook: (no name) - {339a0dff-d9af-439b-92bc-636220fb3dae} - C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Toolbar BHO - {55cde9e7-696c-47c4-8e21-7210b8aeb103} - C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbar.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\100402935\ICQToolBar.dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files\DVDVideoSoft\tbDVD1.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.


Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 14:57
od mEEEgy
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.60.1.1000
www.malwarebytes.org

Verze databáze: v2012.02.07.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19170
Zuzanka :: ZUZANKA-PC [administrátor]

Ochrana: Povolena

7.2.2012 14:51:01
mbam-log-2012-02-07 (14-57-20).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 178287
Uplynulý čas: 6 minut, 12 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 49
HKCR\CLSID\{339a0dff-d9af-439b-92bc-636220fb3dae} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{339A0DFF-D9AF-439B-92BC-636220FB3DAE} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{55cde9e7-696c-47c4-8e21-7210b8aeb103} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{6D344995-CB1B-484F-BE8F-C891C3647380} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{03838663-73EE-48D3-86CB-37713F517E4C} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SmileyCentralIE_1wbar Uninstall (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55CDE9E7-696C-47C4-8E21-7210B8AEB103} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{55CDE9E7-696C-47C4-8E21-7210B8AEB103} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55CDE9E7-696C-47C4-8E21-7210B8AEB103} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{d3ca5551-fc2e-4d09-8ece-263607acf9fc} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3CA5551-FC2E-4D09-8ECE-263607ACF9FC} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3CA5551-FC2E-4D09-8ECE-263607ACF9FC} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SYSTEM\CurrentControlSet\Services\SmileyCentralIE_1wService (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{44050974-c002-42b7-9021-d57eef0a0121} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{1169e992-c330-45e8-a499-fce3cfa6d16d} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{4AF6476F-A40F-4040-9C43-56D9BD9E9DEA} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.DataControl.1 (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.DataControl (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44050974-C002-42B7-9021-D57EEF0A0121} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{4136a080-8e5c-4052-a323-4116991a4149} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{320c97a5-6c7c-4f8b-8bbc-92863535885a} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{C25EC67E-EFEB-48C6-872D-9D0B9FF4AC38} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{2124f2ef-929d-45f7-b380-fc24825e448e} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.DynamicBarButton.1 (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.DynamicBarButton (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{6faa4c31-1606-45b1-9f44-5e7d3842d4dd} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{49c8df9e-052d-4640-92b8-17887723d296} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{1DFA47F0-BB0B-4428-95D5-627EAF3959D9} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.HTMLPanel.1 (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.HTMLPanel (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6FAA4C31-1606-45B1-9F44-5E7D3842D4DD} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{2E97A836-86C6-4AC3-9E75-70125D5E35F0} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.HTMLMenu.1 (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.HTMLMenu (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2E97A836-86C6-4AC3-9E75-70125D5E35F0} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{771A3FCC-EDB0-43EB-A2E5-780E113F3736} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{15581CAA-34D1-4247-BBE9-271F93626353} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{81a5a8f8-b9df-4789-86e7-4655656753b6} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{2c079a79-bcb4-4ff0-94e2-47ccff204414} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{08D585DC-E298-4EF4-AB26-73B0909F84F2} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{2de6a158-243f-4b78-81ff-49f663abda0a} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{a249847c-445e-49e7-959e-ee264d620974} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{22081F79-3087-4961-8F5D-D3D4C04EDDCB} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.XMLSessionPlugin.1 (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\SmileyCentralIE_1w.XMLSessionPlugin (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2DE6A158-243F-4B78-81FF-49F663ABDA0A} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\CLSID\{1e24286f-078c-46e2-8d63-c18bc026660e} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\TypeLib\{e5e931e6-2bbc-49eb-90c0-f68f7a8c9130} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
HKCR\Interface\{0EE92756-C20E-4686-A602-0A73A1E3D453} (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.

Nalezené hodnoty v registru: 3
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{D3CA5551-FC2E-4D09-8ECE-263607ACF9FC} (PUP.Adware.FunWeb) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d3ca5551-fc2e-4d09-8ece-263607acf9fc} (PUP.Adware.FunWeb) -> Data: -> Žádná instrukce nebyla provedena.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SmileyCentralIE_1w Browser Plugin Loader (PUP.Adware.FunWeb) -> Data: C:\PROGRA~1\SMILEY~2\bar\1.bin\1wbrmon.exe -> Žádná instrukce nebyla provedena.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 8
C:\ProgramData\95522124 (Rogue.Multiple) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\chrome (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\History (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\Message (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\Settings (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.

Nalezené soubory: 26
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wSrcAs.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbar.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Users\Public\Desktop\MP3 Downloader.lnk (Rogue.Link) -> Žádná instrukce nebyla provedena.
C:\Users\Zuzanka\Desktop\Security Tool.lnk (Rogue.SecurityTool) -> Žádná instrukce nebyla provedena.
C:\Users\Zuzanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk (Rogue.SecurityTool) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbarsvc.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wauxstb.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbrmon.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wbrstub.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wdatact.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wdlghk.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wdyn.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1whighin.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1whtml.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1whtmlmu.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1whttpct.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1widle.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wimpipe.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wmedint.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wmsg.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wregiet.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wskin.dll (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\1wskplay.exe (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\1.bin\LOGO.BMP (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\Message\COMMON.T8S (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.
C:\Program Files\SmileyCentralIE_1w\bar\Settings\s_pid.dat (PUP.Adware.FunWeb) -> Žádná instrukce nebyla provedena.

(konec)


Co dál?

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 16:19
od jaro3
Odinstaluj SmileyCentralIE.

. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Ukaž výsledky
- ujisti se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Odstranit označené
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Můžeš sem pak vložit nový log z MbAM.

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 17:48
od mEEEgy
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware) 1.60.1.1000
www.malwarebytes.org

Verze databáze: v2012.02.07.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19170
Zuzanka :: ZUZANKA-PC [administrátor]

Ochrana: Povolena

7.2.2012 17:21:00
mbam-log-2012-02-07 (17-21-00).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 179225
Uplynulý čas: 7 minut, 58 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)



ComboFix 12-02-07.01 - Zuzanka 07.02.2012 17:35:26.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2006.996 [GMT 1:00]
Spuštěný z: c:\users\Zuzanka\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\RadioWidget.xul
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\facebook.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\googleplus.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-close.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-minimize.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radiobeta.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\splitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\twitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\facebook.gif
c:\program files\Dealio Toolbar\Res\googleplus.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\radio-close.gif
c:\program files\Dealio Toolbar\Res\radio-minimize.gif
c:\program files\Dealio Toolbar\Res\radiobeta.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_baidu.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\search_yandex.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\twitter.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Mozilla Firefox\components\AskHPRFF.js
c:\programdata\hpe10DC.dll
c:\programdata\hpe162E.dll
c:\users\Zuzanka\AppData\Roaming\Desktopicon
c:\users\Zuzanka\AppData\Roaming\Desktopicon\eBay.ico
c:\users\Zuzanka\AppData\Roaming\Desktopicon\uninst.exe
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\wbem\Performance\WmiApRpl_new.ini
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-07 do 2012-02-07 )))))))))))))))))))))))))))))))
.
.
2012-02-07 16:15 . 2012-02-07 16:15 -------- d-----w- c:\users\Zuzanka\AppData\Local\Adobe
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Malwarebytes
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\programdata\Malwarebytes
2012-02-07 13:50 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-07 12:33 . 2012-02-07 12:33 388096 ----a-r- c:\users\Zuzanka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-02-07 12:33 . 2012-02-07 12:33 -------- d-----w- c:\program files\Trend Micro
2012-02-06 22:02 . 2012-02-07 13:44 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Xfire
2012-02-06 22:02 . 2012-02-07 02:00 -------- d-----w- c:\programdata\Xfire
2012-02-06 22:02 . 2012-02-06 22:02 -------- d-----w- c:\program files\Xfire
2012-02-06 21:13 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-02-06 21:13 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-02-06 21:13 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
2012-02-06 21:13 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
2012-02-06 21:13 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-02-06 21:13 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
2012-02-05 13:41 . 2012-02-06 20:58 -------- d-----w- C:\## aswSnx private storage
2012-02-04 17:21 . 2012-02-04 17:21 -------- d-----w- c:\program files\Common Files\Spigot
2012-02-04 17:20 . 2012-02-04 17:20 -------- d-----w- c:\program files\Free Easy Burner
2012-02-04 15:10 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2532A425-F669-463D-A7DE-F11B99FE0AF8}\mpengine.dll
2012-02-03 09:31 . 2012-02-03 09:31 42392 ----a-w- c:\windows\system32\xfcodec.dll
2012-01-26 17:10 . 2012-01-26 17:10 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Canneverbe Limited
2012-01-26 17:08 . 2012-02-05 13:34 -------- d-----w- c:\program files\CDBurnerXP
2012-01-26 17:08 . 2012-01-26 17:08 -------- d-----w- c:\programdata\Canneverbe Limited
2012-01-26 16:39 . 2012-01-26 16:39 -------- d-----w- c:\program files\Microsoft Silverlight
2012-01-11 09:24 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-01-11 09:24 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-01-11 09:24 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 09:24 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-01-11 09:24 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-01-11 09:24 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 09:24 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 09:24 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-26 23:21 . 2009-10-03 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-11-23 13:37 . 2011-12-15 05:18 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-11-16 16:23 . 2012-02-06 21:13 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-06 39408]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-07-02 671608]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296]
"Badoo Desktop"="c:\programdata\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe" [2011-10-05 1051760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-17 196608]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-22 3810304]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-11-04 2087424]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-12-22 483420]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" [2009-09-22 156672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
c:\users\Zuzanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-4 393216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-5 752168]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-9 1616976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2008-12-22 81920]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-07 c:\windows\Tasks\DriverScanner.job
- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2011-08-04 09:22]
.
2012-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 20:18]
.
2012-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 20:18]
.
2011-12-28 c:\windows\Tasks\Norton Security Scan for Zuzanka.job
- c:\progra~1\NORTON~2\Engine\361~1.11\Nss.exe [2011-11-23 07:47]
.
2012-02-06 c:\windows\Tasks\User_Feed_Synchronization-{51360386-A68F-42C8-90FE-A85008D3F352}.job
- c:\windows\system32\msfeedssync.exe [2011-12-15 04:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://puvodni.centrum.cz/
IE: Download Video by Free YouTuBe Utility - c:\program files\Free YouTuBe Utility\IEydown.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
FF - ProfilePath - c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: DVDVideoSoft Toolbar: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - %profile%\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-BitComet - c:\program files\BitComet\BitComet.exe
AddRemove-eBay Icon - c:\users\Zuzanka\AppData\Roaming\Desktopicon\uninst.exe
AddRemove-Free Audio CD Burner_is1 - c:\program files\DVDVideoSoft\Free Audio CD Burner\unins000.exe
AddRemove-Free YouTube to MP3 Converter_is1 - c:\program files\DVDVideoSoft\Free YouTube to MP3 Converter\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-07 17:43
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2012-02-07 17:46:49
ComboFix-quarantined-files.txt 2012-02-07 16:46
.
Před spuštěním: Volných bajtů: 30 220 918 784
Po spuštění: Volných bajtů: 30 062 776 320
.
- - End Of File - - 1002805984A9A58606DEA38189039105

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 18:06
od jaro3
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

Firefox::
FF - ProfilePath - c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: DVDVideoSoft Toolbar: {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - %profile%\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}

RegNull::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]

RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 18:28
od mEEEgy
ComboFix 12-02-07.01 - Zuzanka 07.02.2012 18:13:43.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2006.920 [GMT 1:00]
Spuštěný z: c:\users\Zuzanka\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Zuzanka\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components\ITB_History.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\prefs.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences\user.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome.manifest
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\about.xul
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\autocomplete.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\exitobserver.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\globals.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\highlight.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtabs.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\icqtoolbar.xul
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgLarge.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\bgSmall.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonBlue.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\buttonGreen.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img\searchLogo.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\localfileupdate.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\menu-button.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_bg.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_cz.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_de.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_en.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_es.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_fr.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_he.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_it.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_ru.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_sk.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_tr.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\newTab_uk.html
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\options.xul
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsegamesxml.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\parsemenuxml.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\peoplesearch.xul
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\prefutils.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\search.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\sitespanel.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\splitter.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\statistics.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\tabcontext.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\utilities.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\voucher.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\zoom.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\icq_locale.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\itb_options.dtd
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr\options.properties
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\about.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\abt.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ain.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\ang.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\arrow_eng.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\arrow_heb.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\btn_bg.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\btn_bg_lite.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\default.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dis.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\dropmarker.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\20minutos.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\about.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\abv.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\aktuality.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\aktualne.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\alljobs.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\allocine.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\allradioru.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\altervista.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\amazon.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\answers.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\aol.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\aolradio.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\apple.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ard.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\as.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\atlas.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\atlassk.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\aufeminin.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\autobazar.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\autobazar1.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\autocz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\azet.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bazos.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bbc.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bbc.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bigmir.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\billiger.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bing.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\blesk.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\bleskove.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\btv.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\calcalist.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\canliradyodinle.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\cas.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\cdiscount.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\centrum.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ciao.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\cnet.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\cnn.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\commentcamarche.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\coolsite.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\corriere.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\csfd.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\d.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\dailymotion.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\data.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\deezer.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\default.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\delicious.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\depositfiles.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\deviantart.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\diary.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\digg.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\dir.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\disney.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\diva.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\dnevnik.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\doctissimo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\donanimhaber.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ebay.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ebayanuncios.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ekolay.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\elmundo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\elpais.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\eurosport.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\expats.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\facebook.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\finance.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\firmy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\flickr.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\flix.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\fotolog.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\fox.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\france2.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\free.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\garanti.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gazeta.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gazetevatan.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gazzetta.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gbg.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gepime.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gismeteo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gittigidiyor.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\globes.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gmail.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\gmx.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\google.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\googleearth.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\googletranslate.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\grooveshark.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\haaretz.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\haaretz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\haber7.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\haberturk.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\hepsiburada.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\horadot.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\horoskopy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\hurriyet.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\championat.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\chip.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\icq.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\idnes.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ilike.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ilmeteo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\imageshack.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\imdb.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\impulse.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\infojobs.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\interfacelift.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\internethaber.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\iserialy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\itop.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\iua.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\izlesene.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\jappy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\jeux.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\jeuxvideo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\jing.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\joj.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\kijiji.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\kinopoisk.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\korrespondent.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\lastfm.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\leboncoin.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\lemonde.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\lenta.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\leonardo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\lequipe.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\libero.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\libimseti.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\lide.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\linternaute.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\livejournal.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\los40.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mailru.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mako.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mappy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mapy.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\marca.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\marketgid.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\markiza.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\megavideo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\meinvz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mekusharim.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\meta.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\milanobakeca.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\milliyet.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mimibazar.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\minibazar.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mobilen.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\morfix.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mouse.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\mymovies.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\myspace.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\najisto.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\nana.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\nana10.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\netgames.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\netlog.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\novinky.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\novoteka.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\nrg.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ntvmsnbc.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\nytimes.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\odnoklassniki.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\one.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\orange.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\otto.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\pagesjaunes.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\peliculasyonkis.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\photobucket.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\picnik.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\playcz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\pravda.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\predavatel.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\profesia.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\prosieben.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\r10.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\r101.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\radiode.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rapidshare.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rbc.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\repubblica.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rian.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rozetka.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rozhlas.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\rtl.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sabah.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sahibinden.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sat1.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\segundamano.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\seriesyonkis.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\seznam.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\seznamemail.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sfr.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\shmu.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\schuelervz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\skyrock.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\slsp.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sme.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\snimka.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\softonic.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\spiegel.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\splinder.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sport-express.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sport5.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sportal.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sportcz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sportes.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\sporx.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\stahuj.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\stream.bmp
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\stream.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\studivz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\subito.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\supercz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\superhry.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\svejo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\t-online.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\tapuz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\taringa.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\telecinco.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\terra.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\tf1.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\themarker.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\tiscali.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\topky.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\torrents.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\travian.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\tv.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\twitter.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ucoz.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ukr.ico
.

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 18:28
od mEEEgy
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\vbox7.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\vesti.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\vimeo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\virgilio.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\vkontakte.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\vodafone.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\walla.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wallmart.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\walmart.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wamba.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wat.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\weather.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\web.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wer-kennt-wen.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wetter.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wikipedia.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\wolframalpha.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\yad2.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\yahoo.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\ynet.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\youtube.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\zamunda.bmp
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\zap.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\favicon\zena.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\hide.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\icons.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\logo_small.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\menu.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_r.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\more_vouchers_y.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\options.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\peoplesearch.css
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\pin.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\pinc.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\powerd1.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\remove.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\reset.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\search_arrow.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\search_bg.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\unpin.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin\voucher_bg_y.png
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\install.rdf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\manifest.mf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.rsa
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF\zigbert.sf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.src
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine\icqplugin.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\blacklist.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_11.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_22.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_33.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_34.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_359.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_380.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_39.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_42.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_4201.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_49.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_7.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_90.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\local_sites_972.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\sites\voucher_list.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\ConduitAutoCompleteSearch.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\ConduitAutoCompleteSearch.xpt
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\ConduitToolbar.idl
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\ConduitToolbar.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\ConduitToolbar.xpt
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.dll
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\FFExternalAlert.xpt
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\npmozax.dll
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\nsAxSecurityPolicy.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components\nsIMozAxPlugin.xpt
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\defaults\default_radio_skin.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome.manifest
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome\dvdvideosoft.jar
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\install.rdf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\lib\xpcom.js
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\META-INF\manifest.mf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\META-INF\zigbert.rsa
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\META-INF\zigbert.sf
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin\conduit.gif
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin\conduit.ico
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin\conduit.PNG
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin\conduit.src
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin\conduit.xml
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\setup.ini
c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\version.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-07 do 2012-02-07 )))))))))))))))))))))))))))))))
.
.
2012-02-07 17:21 . 2012-02-07 17:21 -------- d-----w- c:\users\Zuzanka\AppData\Local\temp
2012-02-07 17:21 . 2012-02-07 17:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-07 17:03 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D8B33F76-F4E7-4071-9FEB-40A331062E97}\mpengine.dll
2012-02-07 16:15 . 2012-02-07 16:15 -------- d-----w- c:\users\Zuzanka\AppData\Local\Adobe
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Malwarebytes
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-07 13:50 . 2012-02-07 13:50 -------- d-----w- c:\programdata\Malwarebytes
2012-02-07 13:50 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-07 12:33 . 2012-02-07 12:33 388096 ----a-r- c:\users\Zuzanka\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-02-07 12:33 . 2012-02-07 12:33 -------- d-----w- c:\program files\Trend Micro
2012-02-06 22:02 . 2012-02-07 13:44 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Xfire
2012-02-06 22:02 . 2012-02-07 02:00 -------- d-----w- c:\programdata\Xfire
2012-02-06 22:02 . 2012-02-06 22:02 -------- d-----w- c:\program files\Xfire
2012-02-06 21:13 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-02-06 21:13 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-02-06 21:13 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
2012-02-06 21:13 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
2012-02-06 21:13 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-02-06 21:13 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
2012-02-05 13:41 . 2012-02-06 20:58 -------- d-----w- C:\## aswSnx private storage
2012-02-04 17:21 . 2012-02-04 17:21 -------- d-----w- c:\program files\Common Files\Spigot
2012-02-04 17:20 . 2012-02-04 17:20 -------- d-----w- c:\program files\Free Easy Burner
2012-02-03 09:31 . 2012-02-03 09:31 42392 ----a-w- c:\windows\system32\xfcodec.dll
2012-01-26 17:10 . 2012-01-26 17:10 -------- d-----w- c:\users\Zuzanka\AppData\Roaming\Canneverbe Limited
2012-01-26 17:08 . 2012-02-05 13:34 -------- d-----w- c:\program files\CDBurnerXP
2012-01-26 17:08 . 2012-01-26 17:08 -------- d-----w- c:\programdata\Canneverbe Limited
2012-01-26 16:39 . 2012-01-26 16:39 -------- d-----w- c:\program files\Microsoft Silverlight
2012-01-11 09:24 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-01-11 09:24 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-01-11 09:24 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 09:24 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-01-11 09:24 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-01-11 09:24 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 09:24 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 09:24 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-26 23:21 . 2009-10-03 12:18 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-11-23 13:37 . 2011-12-15 05:18 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-11-16 16:23 . 2012-02-06 21:13 278528 ----a-w- c:\windows\system32\schannel.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-06 39408]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2010-07-02 671608]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2011-05-16 338296]
"Badoo Desktop"="c:\programdata\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe" [2011-10-05 1051760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-17 196608]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-22 3810304]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-11-04 2087424]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-12-22 483420]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Ask and Record FLV Service"="c:\program files\Replay Media Catcher\FLVSrvc.exe" [2009-09-22 156672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
.
c:\users\Zuzanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-10-4 393216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-5 752168]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-9 1616976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2008-12-22 81920]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-07 c:\windows\Tasks\DriverScanner.job
- c:\program files\Uniblue\DriverScanner\dsmonitor.exe [2011-08-04 09:22]
.
2012-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 20:18]
.
2012-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-24 20:18]
.
2011-12-28 c:\windows\Tasks\Norton Security Scan for Zuzanka.job
- c:\progra~1\NORTON~2\Engine\361~1.11\Nss.exe [2011-11-23 07:47]
.
2012-02-06 c:\windows\Tasks\User_Feed_Synchronization-{51360386-A68F-42C8-90FE-A85008D3F352}.job
- c:\windows\system32\msfeedssync.exe [2011-12-15 04:44]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://puvodni.centrum.cz/
IE: Download Video by Free YouTuBe Utility - c:\program files\Free YouTuBe Utility\IEydown.htm
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 10.0.0.138 10.0.0.138
FF - ProfilePath - c:\users\Zuzanka\AppData\Roaming\Mozilla\Firefox\Profiles\lg6xd3l1.default\
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-RunOnce-SuperMp3Downloadunstall - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-07 18:21
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2012-02-07 18:23:21
ComboFix-quarantined-files.txt 2012-02-07 17:23
ComboFix2.txt 2012-02-07 16:46
.
Před spuštěním: Volných bajtů: 29 684 674 560
Po spuštění: Volných bajtů: 29 935 427 584
.
- - End Of File - - 0D12FD106357DE19E6F755F8E99A4848

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 18:28
od mEEEgy
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:24:27, on 7.2.2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19170)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Replay Media Catcher\FLVSrvc.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://puvodni.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ask and Record FLV Service] "C:\Program Files\Replay Media Catcher\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKCU\..\Run: [Badoo Desktop] C:\ProgramData\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Download Video by Free YouTuBe Utility - C:\Program Files\Free YouTuBe Utility\IEydown.htm
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Služba Google Update (gupdate1cafb7e4917c4d0) (gupdate1cafb7e4917c4d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: WTGService - Unknown owner - C:\Program Files\Verbindungsassistent\wtgservice.exe

--
End of file - 9637 bytes

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 21:06
od jaro3
ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Vyčisti systém CCleanerem
a použij i T-Cleaner
smaže vše po Combu,MWAVu atd.-stáhneš>spustíš

pozn. před stažením T-Cleaneru a po dobu čištění deaktivuj antivir a antispyware ,následně T-Cleaner smaž a zapni si znovu antivir a antispyware.


Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"


Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.

Re: Kontrola logu- zasekávání

Napsal: 07 úno 2012 21:27
od mEEEgy
Děkuju moc, systém se zrychlil, fakt moc dík. :)