Pouzil jsem ho vymazani viru Policie CR.
Díky.
► Zobrazit spoiler
ComboFix 13-04-12.02 - Petr 12.04.2013 20:28:55.1.2 - x64 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.4094.3324 [GMT 2:00]
Spuštěný z: F:\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\cflog\CrashLog_20110903.txt
C:\install.exe
c:\program files (x86)\BFlix\BFLIx.dll
c:\program files (x86)\BrowserCompanion
c:\program files (x86)\BrowserCompanion\BCHelper.exe
c:\program files (x86)\BrowserCompanion\blabbers-ff-full.xpi
c:\program files (x86)\BrowserCompanion\blabbers-ch.crx
c:\program files (x86)\BrowserCompanion\jsloader.dll
c:\program files (x86)\BrowserCompanion\logo.ico
c:\program files (x86)\BrowserCompanion\sqlite3.dll
c:\program files (x86)\BrowserCompanion\tdataprotocol.dll
c:\program files (x86)\BrowserCompanion\toolbar.dll
c:\program files (x86)\BrowserCompanion\uninstall.exe
c:\program files (x86)\BrowserCompanion\updater.ini
c:\program files (x86)\BrowserCompanion\widgetserv.exe
c:\program files (x86)\Funmoods
c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortApp.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortEng.dll
c:\program files (x86)\Funmoods\1.5.23.22\escorTlbr.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortShld.dll
c:\program files (x86)\Funmoods\1.5.23.22\FavIcon.ico
c:\program files (x86)\Funmoods\1.5.23.22\funmoodssrv.exe
c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe
c:\program files (x86)\GadgetBox\gaDGetboxtb.dll
c:\program files (x86)\RelevantKnowledge
c:\program files (x86)\RelevantKnowledge\ncncf.dat
c:\program files (x86)\RelevantKnowledge\nscf.dat
c:\program files (x86)\RelevantKnowledge\rloci.bin
c:\program files (x86)\SaveTubeVideo.com
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\BrowserStartPage.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Config.dat
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\downloader.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\allkeywords.txt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\ISwslib.xpt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\nsIRdsHistoryService.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\nsIRdsHistoryService.xpt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\rdstb-autocomplete.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\swslib.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome.manifest
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\about.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\GoogleFeed.xml
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\GoogleSearch.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\registerdialog.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\registerdialog.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\settings.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\skysearchtoolbar.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\skysearchtoolbar.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\startAbout.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\unregister.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\locale\en-US\skysearchtoolbar.dtd
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\locale\en-US\toolbar.properties
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\about.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\aboutDlg.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\addvideo.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\bigbutton.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\burnit.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\gripper.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\icon.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\icon16-16.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\register.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\savevideo.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\savevideo2.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\search.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\settings.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\showstatus.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\skysearchtoolbar.css
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\smile!.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\videooftheday.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\install.rdf
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\SearchToolbar@skywebsearch.com
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FLVSplitter.ax
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\index.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\manifest.json
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\redirect.html
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\GoogleChromeExtansion.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\index.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\InstallHelper.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\lame.ax
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\MinBHO.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\PreferencesOriginal
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\RegSetup.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SaVEtubevideo.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SeARchbho.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\StarBurnRDS.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\transport_dll.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.dat
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Web Data-journal
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Web Data
c:\programdata\100
c:\programdata\ADDICT-THING
c:\programdata\ADDICT-THING\background.html
c:\programdata\ADDICT-THING\bhoclass.dl
c:\programdata\ADDICT-THING\bhoclass.dll
c:\programdata\ADDICT-THING\content.js
c:\programdata\ADDICT-THING\data\content.js
c:\programdata\ADDICT-THING\data\jsondb.js
c:\programdata\ADDICT-THING\kiijcmkcmfcceoephfgfmggjgjjglkji.crx
c:\programdata\ADDICT-THING\nefpcghdfphcclbhdcjdilfiiepjhbog.crx
c:\programdata\ADDICT-THING\settings.ini
c:\programdata\ADDICT-THING\uninstall.exe
c:\programdata\bProtector
c:\programdata\bProtector\bProtect.exe
c:\programdata\bProtector\bProtect.settings
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING\ADDICT-THING.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING\Uninstall.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Member of GRID - Goodware Repository Information Database.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Recent\httpdailyustime.comwp-contentuploads201202Teen-n-Beauty-1.gif.URL
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\chrome.manifest
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\install.rdf
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf
c:\users\Petr\AppData\Roaming\skype.dat
c:\users\Petr\AppData\Roaming\skype.ini
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_RelevantKnowledge
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-12 do 2013-04-12 )))))))))))))))))))))))))))))))
.
.
2013-04-12 18:35 . 2013-04-12 18:37 -------- d-----w- c:\users\Petr\AppData\Local\temp
2013-04-12 05:27 . 2013-04-12 05:27 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-04-10 16:19 . 2013-02-15 06:06 3717632 ----a-w- c:\windows\system32\mstscax.dll
2013-04-10 16:19 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\SysWow64\mstscax.dll
2013-04-10 16:19 . 2013-02-15 06:08 44032 ----a-w- c:\windows\system32\tsgqec.dll
2013-04-10 16:19 . 2013-02-15 06:02 158720 ----a-w- c:\windows\system32\aaclient.dll
2013-04-10 16:19 . 2013-02-15 04:34 131584 ----a-w- c:\windows\SysWow64\aaclient.dll
2013-04-10 16:19 . 2013-02-15 03:25 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2013-04-10 16:17 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 16:17 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 16:17 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-04-10 16:17 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-04-10 16:17 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-10 16:17 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-04-10 16:17 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe
2013-04-01 07:16 . 2013-04-01 07:16 -------- d-----w- c:\program files (x86)\DsNET Corp
2013-03-31 11:58 . 2009-05-19 16:32 758018 ----a-w- c:\windows\SysWow64\xvidcore.dll
2013-03-31 11:58 . 2008-12-04 19:46 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2013-03-31 11:58 . 2008-10-08 08:16 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2013-03-31 09:58 . 2013-03-31 10:13 -------- d-----w- C:\video_output
2013-03-31 09:29 . 2013-04-01 10:41 -------- d-----w- c:\program files (x86)\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2013-03-30 18:45 . 2013-03-30 18:45 -------- d-----w- c:\program files (x86)\Seznam.cz
2013-03-30 18:43 . 2013-04-12 18:03 -------- d-----w- c:\users\Petr\AppData\Roaming\Seznam.cz
2013-03-30 16:52 . 2013-03-30 16:52 -------- d-----w- c:\users\Petr\AppData\Local\AskPartnerNetwork
2013-03-30 16:51 . 2013-03-30 16:51 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-03-30 16:51 . 2013-03-30 16:51 -------- d-----w- c:\program files (x86)\AskPartnerNetwork
2013-03-30 16:39 . 2010-03-15 09:31 165376 ----a-w- c:\windows\SysWow64\unrar.dll
2013-03-30 16:39 . 2013-03-30 16:39 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2013-03-30 16:39 . 2013-03-30 16:39 -------- d-----w- c:\program files (x86)\WinPcap
2013-03-30 10:44 . 2013-03-30 10:44 -------- d-----w- c:\programdata\APN
2013-03-30 08:37 . 2013-03-30 09:37 -------- d-----w- c:\program files (x86)\YouTube Video Downloader
2013-03-30 08:04 . 2013-03-30 08:04 -------- d-----w- c:\users\Petr\AppData\Roaming\Tomabo
2013-03-30 08:04 . 2013-03-30 08:04 -------- d-----w- c:\program files (x86)\Tomabo
2013-03-21 18:33 . 2013-03-21 18:44 -------- d-----w- c:\program files (x86)\FIFA 13
2013-03-20 13:38 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-03-20 13:38 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-03-19 18:22 . 2013-03-19 18:22 -------- d-----w- c:\windows\system32\SPReview
2013-03-19 18:21 . 2013-03-19 18:21 -------- d-----w- c:\windows\system32\EventProviders
2013-03-19 13:44 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-07 08:54 . 2012-09-17 12:46 1455408 ----a-w- c:\windows\system32\dmwu.exe
2013-04-07 08:53 . 2012-09-17 12:46 33792 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-03-19 18:33 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2013-03-19 18:33 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2013-03-13 10:30 . 2012-04-07 12:43 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-13 10:30 . 2012-01-09 07:35 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-18 13:38 . 2012-08-30 18:37 39768 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-02-12 05:45 . 2013-03-20 13:38 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-20 13:38 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-20 13:38 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-20 13:38 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-20 13:38 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-20 13:38 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-05 07:25 . 2011-02-19 21:51 608080 ----a-w- c:\windows\system32\msvcp100.dll
2013-02-05 07:25 . 2011-02-18 23:52 829264 ----a-w- c:\windows\system32\msvcr100.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{D8278076-BC68-4484-9233-6E7F1628B56C}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll" [2013-02-15 130696]
.
[HKEY_CLASSES_ROOT\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}]
[HKEY_CLASSES_ROOT\TypeLib\{7C4EE486-5EA5-4683-8C23-BF520933BB5E}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{20a0be68-8fd9-4539-8712-ce3d1c1fdfc6}]
2011-12-22 21:17 262312 ----a-w- c:\program files (x86)\blekkotb\auxi\blekkoAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
2011-12-22 21:16 86696 ----a-w- c:\program files (x86)\blekkotb\blekkoDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5347542D-5341-5400-76A7-7A786E7484D7}]
2013-02-15 08:27 13448 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-SAT\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5347542D-5636-006A-76A7-7A786E7484D7}]
2013-03-27 05:23 13448 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-V6\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
2012-12-19 10:22 2609864 ----a-w- c:\program files (x86)\IMinent Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-02-18 13:38 1929392 ----a-w- c:\program files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]
2011-12-22 07:44 87488 ----a-w- c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2011-08-24 17:21 1299248 ----a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-12-09 01:11 194848 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll" [2013-02-18 1929392]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files (x86)\Yandex\YandexBarIE\yndbar.dll" [2012-03-05 8921400]
"{26c9e18c-3717-4be1-a225-04e4471f5b6e}"= "c:\program files (x86)\blekkotb\blekkoDx.dll" [2011-12-22 86696]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
"{af6ac4f2-9825-4fb6-a600-92bc5361f209}"= "c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll" [2011-12-22 87488]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files (x86)\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864]
"{5347542D-5636-006A-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-V6\Passport.dll" [2013-03-27 13448]
"{5347542D-5341-5400-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-SAT\Passport.dll" [2013-02-15 13448]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
.
[HKEY_CLASSES_ROOT\clsid\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_CLASSES_ROOT\clsid\{5347542d-5636-006a-76a7-7a786e7484d7}]
.
[HKEY_CLASSES_ROOT\clsid\{5347542d-5341-5400-76a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-12-29 969104]
"SDP"="c:\program files (x86)\FilesFrog Update Checker\update_checker.exe" [2012-05-31 200784]
"Boxoft Tools"="c:\programdata\Boxtools\Boxofttoolbox.exe" [2010-12-15 514048]
"MediaGet2"="c:\users\Petr\AppData\Local\MediaGet2\mediaget.exe" [2013-02-16 10847976]
"Clownfish"="c:\program files (x86)\Clownfish\Clownfish.exe" [2012-09-27 1122040]
"cz.seznam.software.autoupdate"="c:\users\Petr\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Petr\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2012-12-19 92296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-02-28 18642024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2013-02-18 1151152]
"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-12-21 206504]
"Nero MediaHome 4"="c:\program files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-09-24 4859176]
"SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]
"Gridspot"="c:\program files (x86)\Gridspot\Gridspot.exe" [2012-03-20 525168]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" [2012-07-12 1564368]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Iminent"="c:\program files (x86)\Iminent\Iminent.exe" [2012-12-19 1074888]
"IminentMessenger"="c:\program files (x86)\Iminent\Iminent.Messengers.exe" [2012-12-19 884936]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-02-15 1483912]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-08 1255736]
R3 X6va005;X6va005;c:\users\Petr\AppData\Local\Temp\0054A13.tmp [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-11-08 307040]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2013-02-18 39768]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-08 279616]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-02-15 169096]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-11-02 5174392]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 GridspotService;GridspotService;c:\program files (x86)\Gridspot\GridspotService.exe [2012-03-20 51568]
S2 GridspotVMDriver;GridspotVMDriver;c:\program files (x86)\Gridspot\VMRuntime\VBoxDrv.sys [2011-11-04 224048]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2012-07-12 1564368]
S2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [2013-04-07 1455408]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-11 204304]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]
S2 SProtection;SProtection;c:\program files (x86)\Common Files\Umbrella\Umbrella.exe [2012-12-14 2620016]
S2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [2012-06-12 935480]
S2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [2013-02-18 968880]
S2 Web Assistant;Web Assistant;c:\program files\Web Assistant\ExtensionUpdaterService.exe [2013-01-29 188760]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-12-10 127328]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776]
S3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 17:19 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 10:30]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-07 20:07]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-07 20:07]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.iminent.com/?appId=156EE4 ... 572564C2E1
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000&st=18&barid={CFD61237-4204-11E1-AFF4-0016E656F306}
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://downloads.phpnuke.org/en/index.p ... gle&q={searchTerms}
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Search the Web - c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\SpecialSavings\SpecialSavingsSinged.dll
TCP: DhcpNameServer = 192.168.0.1
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.search.selectedengine - search the web (babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT27866 ... hSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... M=UM_ID&q=
FF - prefs.js: keyword.url - hxxp://search.conduit.com/resultsext.as ... ource=2&q=
FF - ExtSQL: 2013-03-01 07:15; {FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}; c:\program files\Web Assistant\Firefox
FF - ExtSQL: 2013-03-30 17:52; toolbar_SGT-V6@apn.ask.com; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\toolbar_SGT-V6@apn.ask.com.xpi
FF - ExtSQL: 2013-03-30 19:40; toolbar_SGT-SAT@apn.ask.com; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\toolbar_SGT-SAT@apn.ask.com.xpi
FF - ExtSQL: 2013-03-30 19:45; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{00cbb66b-1d3b-46d3-9577-323a336acb50} - c:\program files (x86)\BrowserCompanion\jsloader.dll
BHO-{0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - c:\program files (x86)\BFlix\BFlix.dll
BHO-{2863E737-DD3F-4280-9AF8-E9E79C16F312} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\MinBHO.dll
BHO-{72A1C27E-EBB0-789B-470D-4036B4F3C806} - c:\programdata\ADDICT-THING\bhoclass.dll
BHO-{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - c:\progra~2\Funmoods\1.5.23.22\bh\escort.dll
BHO-{99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
BHO-{B1D66BF3-1604-1F8A-A920-B4C0350367E0} - c:\programdata\ADDICT-THING\bhoclass.dll
BHO-{D7BE8ED1-B138-48FD-BB22-9779A39130B1} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SearchBHO.dll
Toolbar-10 - (no file)
Toolbar-{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - c:\progra~2\Funmoods\1.5.23.22\escorTlbr.dll
Toolbar-{99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
Toolbar-{3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - c:\program files (x86)\GadgetBox\gadgetBoxTB.dll
Toolbar-{F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SaveTubeVideo.dll
Wow6432Node-HKLM-Run-Browser companion helper - c:\program files (x86)\BrowserCompanion\BCHelper.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
BHO-{336D0C35-8A85-403a-B9D2-65C292C39087} - (no file)
Toolbar-10 - (no file)
WebBrowser-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
WebBrowser-{5347542D-5636-006A-76A7-7A786E7484D7} - (no file)
WebBrowser-{5347542D-5341-5400-76A7-7A786E7484D7} - (no file)
AddRemove-BrowserCompanion - c:\program files (x86)\BrowserCompanion\uninstall.exe
AddRemove-funmoods - c:\progra~2\Funmoods\1.5.23.22\uninstall.exe
AddRemove-SaveTubeVideo_is1 - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.exe
AddRemove-{71277DC4-4217-462A-9FF4-62D7815B2C69} - c:\programdata\ADDICT-THING\uninstall.exe
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files (x86)\RelevantKnowledge\rlvknlg.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Petr\AppData\Local\Temp\0054A13.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-243381793-2137855970-1547821832-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\progra~2\ICQ6TO~1\ICQSER~1.EXE
c:\program files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\windows\SysWOW64\IoctlSvc.exe
c:\windows\SysWOW64\jmdp\stij.exe
.
**************************************************************************
.
Celkový čas: 2013-04-12 20:43:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-04-12 18:43
.
Před spuštěním: Volných bajtů: 60 246 585 344
Po spuštění: Volných bajtů: 59 986 239 488
.
- - End Of File - - B9D278ED29D13A243E8F0D4ADBCFDAAE
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.4094.3324 [GMT 2:00]
Spuštěný z: F:\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\cflog\CrashLog_20110903.txt
C:\install.exe
c:\program files (x86)\BFlix\BFLIx.dll
c:\program files (x86)\BrowserCompanion
c:\program files (x86)\BrowserCompanion\BCHelper.exe
c:\program files (x86)\BrowserCompanion\blabbers-ff-full.xpi
c:\program files (x86)\BrowserCompanion\blabbers-ch.crx
c:\program files (x86)\BrowserCompanion\jsloader.dll
c:\program files (x86)\BrowserCompanion\logo.ico
c:\program files (x86)\BrowserCompanion\sqlite3.dll
c:\program files (x86)\BrowserCompanion\tdataprotocol.dll
c:\program files (x86)\BrowserCompanion\toolbar.dll
c:\program files (x86)\BrowserCompanion\uninstall.exe
c:\program files (x86)\BrowserCompanion\updater.ini
c:\program files (x86)\BrowserCompanion\widgetserv.exe
c:\program files (x86)\Funmoods
c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortApp.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortEng.dll
c:\program files (x86)\Funmoods\1.5.23.22\escorTlbr.dll
c:\program files (x86)\Funmoods\1.5.23.22\escortShld.dll
c:\program files (x86)\Funmoods\1.5.23.22\FavIcon.ico
c:\program files (x86)\Funmoods\1.5.23.22\funmoodssrv.exe
c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe
c:\program files (x86)\GadgetBox\gaDGetboxtb.dll
c:\program files (x86)\RelevantKnowledge
c:\program files (x86)\RelevantKnowledge\ncncf.dat
c:\program files (x86)\RelevantKnowledge\nscf.dat
c:\program files (x86)\RelevantKnowledge\rloci.bin
c:\program files (x86)\SaveTubeVideo.com
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\BrowserStartPage.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Config.dat
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\downloader.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\allkeywords.txt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\ISwslib.xpt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\nsIRdsHistoryService.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\nsIRdsHistoryService.xpt
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\rdstb-autocomplete.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\components\swslib.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome.manifest
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\about.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\GoogleFeed.xml
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\GoogleSearch.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\registerdialog.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\registerdialog.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\settings.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\skysearchtoolbar.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\skysearchtoolbar.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\startAbout.js
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\content\unregister.xul
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\locale\en-US\skysearchtoolbar.dtd
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\locale\en-US\toolbar.properties
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\about.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\aboutDlg.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\addvideo.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\bigbutton.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\burnit.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\gripper.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\icon.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\icon16-16.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\register.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\savevideo.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\savevideo2.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\search.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\settings.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\showstatus.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\skysearchtoolbar.css
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\smile!.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\chrome\skin\videooftheday.png
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\install.rdf
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FF\SearchToolbar@skywebsearch.com
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\FLVSplitter.ax
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\index.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\manifest.json
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Google Custom Search\redirect.html
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\GoogleChromeExtansion.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\index.htm
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\InstallHelper.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\lame.ax
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\MinBHO.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\PreferencesOriginal
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\RegSetup.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SaVEtubevideo.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SeARchbho.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\StarBurnRDS.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\transport_dll.dll
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.dat
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.exe
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Web Data-journal
c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\Web Data
c:\programdata\100
c:\programdata\ADDICT-THING
c:\programdata\ADDICT-THING\background.html
c:\programdata\ADDICT-THING\bhoclass.dl
c:\programdata\ADDICT-THING\bhoclass.dll
c:\programdata\ADDICT-THING\content.js
c:\programdata\ADDICT-THING\data\content.js
c:\programdata\ADDICT-THING\data\jsondb.js
c:\programdata\ADDICT-THING\kiijcmkcmfcceoephfgfmggjgjjglkji.crx
c:\programdata\ADDICT-THING\nefpcghdfphcclbhdcjdilfiiepjhbog.crx
c:\programdata\ADDICT-THING\settings.ini
c:\programdata\ADDICT-THING\uninstall.exe
c:\programdata\bProtector
c:\programdata\bProtector\bProtect.exe
c:\programdata\bProtector\bProtect.settings
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING\ADDICT-THING.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\ADDICT-THING\Uninstall.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Member of GRID - Goodware Repository Information Database.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Support.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge\Uninstall Instructions.lnk
c:\users\Petr\AppData\Roaming\Microsoft\Windows\Recent\httpdailyustime.comwp-contentuploads201202Teen-n-Beauty-1.gif.URL
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\chrome.manifest
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\install.rdf
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf
c:\users\Petr\AppData\Roaming\skype.dat
c:\users\Petr\AppData\Roaming\skype.ini
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_RelevantKnowledge
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-03-12 do 2013-04-12 )))))))))))))))))))))))))))))))
.
.
2013-04-12 18:35 . 2013-04-12 18:37 -------- d-----w- c:\users\Petr\AppData\Local\temp
2013-04-12 05:27 . 2013-04-12 05:27 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-04-10 16:19 . 2013-02-15 06:06 3717632 ----a-w- c:\windows\system32\mstscax.dll
2013-04-10 16:19 . 2013-02-15 04:37 3217408 ----a-w- c:\windows\SysWow64\mstscax.dll
2013-04-10 16:19 . 2013-02-15 06:08 44032 ----a-w- c:\windows\system32\tsgqec.dll
2013-04-10 16:19 . 2013-02-15 06:02 158720 ----a-w- c:\windows\system32\aaclient.dll
2013-04-10 16:19 . 2013-02-15 04:34 131584 ----a-w- c:\windows\SysWow64\aaclient.dll
2013-04-10 16:19 . 2013-02-15 03:25 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2013-04-10 16:17 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys
2013-04-10 16:17 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 16:17 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-04-10 16:17 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-04-10 16:17 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-04-10 16:17 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-04-10 16:17 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe
2013-04-01 07:16 . 2013-04-01 07:16 -------- d-----w- c:\program files (x86)\DsNET Corp
2013-03-31 11:58 . 2009-05-19 16:32 758018 ----a-w- c:\windows\SysWow64\xvidcore.dll
2013-03-31 11:58 . 2008-12-04 19:46 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2013-03-31 11:58 . 2008-10-08 08:16 139264 ----a-w- c:\windows\SysWow64\xvid.ax
2013-03-31 09:58 . 2013-03-31 10:13 -------- d-----w- C:\video_output
2013-03-31 09:29 . 2013-04-01 10:41 -------- d-----w- c:\program files (x86)\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2013-03-30 18:45 . 2013-03-30 18:45 -------- d-----w- c:\program files (x86)\Seznam.cz
2013-03-30 18:43 . 2013-04-12 18:03 -------- d-----w- c:\users\Petr\AppData\Roaming\Seznam.cz
2013-03-30 16:52 . 2013-03-30 16:52 -------- d-----w- c:\users\Petr\AppData\Local\AskPartnerNetwork
2013-03-30 16:51 . 2013-03-30 16:51 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-03-30 16:51 . 2013-03-30 16:51 -------- d-----w- c:\program files (x86)\AskPartnerNetwork
2013-03-30 16:39 . 2010-03-15 09:31 165376 ----a-w- c:\windows\SysWow64\unrar.dll
2013-03-30 16:39 . 2013-03-30 16:39 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2013-03-30 16:39 . 2013-03-30 16:39 -------- d-----w- c:\program files (x86)\WinPcap
2013-03-30 10:44 . 2013-03-30 10:44 -------- d-----w- c:\programdata\APN
2013-03-30 08:37 . 2013-03-30 09:37 -------- d-----w- c:\program files (x86)\YouTube Video Downloader
2013-03-30 08:04 . 2013-03-30 08:04 -------- d-----w- c:\users\Petr\AppData\Roaming\Tomabo
2013-03-30 08:04 . 2013-03-30 08:04 -------- d-----w- c:\program files (x86)\Tomabo
2013-03-21 18:33 . 2013-03-21 18:44 -------- d-----w- c:\program files (x86)\FIFA 13
2013-03-20 13:38 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-03-20 13:38 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe
2013-03-19 18:22 . 2013-03-19 18:22 -------- d-----w- c:\windows\system32\SPReview
2013-03-19 18:21 . 2013-03-19 18:21 -------- d-----w- c:\windows\system32\EventProviders
2013-03-19 13:44 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-07 08:54 . 2012-09-17 12:46 1455408 ----a-w- c:\windows\system32\dmwu.exe
2013-04-07 08:53 . 2012-09-17 12:46 33792 ----a-w- c:\windows\system32\ImHttpComm.dll
2013-03-19 18:33 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2013-03-19 18:33 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2013-03-13 10:30 . 2012-04-07 12:43 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-03-13 10:30 . 2012-01-09 07:35 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-18 13:38 . 2012-08-30 18:37 39768 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-02-12 05:45 . 2013-03-20 13:38 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-02-12 05:45 . 2013-03-20 13:38 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-02-12 05:45 . 2013-03-20 13:38 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-02-12 05:45 . 2013-03-20 13:38 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-02-12 04:48 . 2013-03-20 13:38 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-02-12 04:48 . 2013-03-20 13:38 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-02-05 07:25 . 2011-02-19 21:51 608080 ----a-w- c:\windows\system32\msvcp100.dll
2013-02-05 07:25 . 2011-02-18 23:52 829264 ----a-w- c:\windows\system32\msvcr100.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{D8278076-BC68-4484-9233-6E7F1628B56C}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\searchhook.dll" [2013-02-15 130696]
.
[HKEY_CLASSES_ROOT\clsid\{d8278076-bc68-4484-9233-6e7f1628b56c}]
[HKEY_CLASSES_ROOT\TypeLib\{7C4EE486-5EA5-4683-8C23-BF520933BB5E}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{20a0be68-8fd9-4539-8712-ce3d1c1fdfc6}]
2011-12-22 21:17 262312 ----a-w- c:\program files (x86)\blekkotb\auxi\blekkoAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
2011-12-22 21:16 86696 ----a-w- c:\program files (x86)\blekkotb\blekkoDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5347542D-5341-5400-76A7-7A786E7484D7}]
2013-02-15 08:27 13448 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-SAT\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5347542D-5636-006A-76A7-7A786E7484D7}]
2013-03-27 05:23 13448 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-V6\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
2012-12-19 10:22 2609864 ----a-w- c:\program files (x86)\IMinent Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{7DA17D5A-5718-4130-A605-FC316C827836}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-02-18 13:38 1929392 ----a-w- c:\program files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]
2011-12-22 07:44 87488 ----a-w- c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2011-08-24 17:21 1299248 ----a-r- c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-12-09 01:11 194848 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll" [2013-02-18 1929392]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files (x86)\Yandex\YandexBarIE\yndbar.dll" [2012-03-05 8921400]
"{26c9e18c-3717-4be1-a225-04e4471f5b6e}"= "c:\program files (x86)\blekkotb\blekkoDx.dll" [2011-12-22 86696]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files (x86)\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
"{af6ac4f2-9825-4fb6-a600-92bc5361f209}"= "c:\progra~2\SEARCH~1\Datamngr\ToolBar\searchcoredtx.dll" [2011-12-22 87488]
"{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files (x86)\IMinent Toolbar\tbcore3.dll" [2012-12-19 2609864]
"{5347542D-5636-006A-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-V6\Passport.dll" [2013-03-27 13448]
"{5347542D-5341-5400-76A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\SGT-SAT\Passport.dll" [2013-02-15 13448]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
.
[HKEY_CLASSES_ROOT\clsid\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{af6ac4f2-9825-4fb6-a600-92bc5361f209}]
.
[HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\TBSB01620.TBSB01620]
.
[HKEY_CLASSES_ROOT\clsid\{5347542d-5636-006a-76a7-7a786e7484d7}]
.
[HKEY_CLASSES_ROOT\clsid\{5347542d-5341-5400-76a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"uTorrent"="c:\program files (x86)\uTorrent\uTorrent.exe" [2012-12-29 969104]
"SDP"="c:\program files (x86)\FilesFrog Update Checker\update_checker.exe" [2012-05-31 200784]
"Boxoft Tools"="c:\programdata\Boxtools\Boxofttoolbox.exe" [2010-12-15 514048]
"MediaGet2"="c:\users\Petr\AppData\Local\MediaGet2\mediaget.exe" [2013-02-16 10847976]
"Clownfish"="c:\program files (x86)\Clownfish\Clownfish.exe" [2012-09-27 1122040]
"cz.seznam.software.autoupdate"="c:\users\Petr\AppData\Roaming\Seznam.cz\szninstall.exe" [2012-09-13 1009288]
"cz.seznam.software.szndesktop"="c:\users\Petr\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2012-12-19 92296]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-02-28 18642024]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2013-02-18 1151152]
"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-12-21 206504]
"Nero MediaHome 4"="c:\program files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe" [2009-09-24 4859176]
"SweetIM"="c:\program files (x86)\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]
"Gridspot"="c:\program files (x86)\Gridspot\Gridspot.exe" [2012-03-20 525168]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Guard.Mail.ru.gui"="c:\program files (x86)\Guard-ICQ\GuardICQ.exe" [2012-07-12 1564368]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Iminent"="c:\program files (x86)\Iminent\Iminent.exe" [2012-12-19 1074888]
"IminentMessenger"="c:\program files (x86)\Iminent\Iminent.Messengers.exe" [2012-12-19 884936]
"ApnTBMon"="c:\program files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-02-15 1483912]
"seznam-listicka-distribuce"="c:\program files (x86)\Seznam.cz\distribution\szninstall.exe" [2012-09-13 1009288]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-08 1255736]
R3 X6va005;X6va005;c:\users\Petr\AppData\Local\Temp\0054A13.tmp [x]
R3 X6va011;X6va011;c:\windows\SysWOW64\Drivers\X6va011 [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-11-08 307040]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-08-24 384352]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2013-02-18 39768]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-01-08 279616]
S2 APNMCP;Ask Update Service;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [2013-02-15 169096]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2012-11-02 5174392]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288]
S2 GridspotService;GridspotService;c:\program files (x86)\Gridspot\GridspotService.exe [2012-03-20 51568]
S2 GridspotVMDriver;GridspotVMDriver;c:\program files (x86)\Gridspot\VMRuntime\VBoxDrv.sys [2011-11-04 224048]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files (x86)\Guard-ICQ\GuardICQ.exe [2012-07-12 1564368]
S2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [2013-04-07 1455408]
S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-11 204304]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35344]
S2 SProtection;SProtection;c:\program files (x86)\Common Files\Umbrella\Umbrella.exe [2012-12-14 2620016]
S2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [2012-06-12 935480]
S2 vToolbarUpdater14.2.0;vToolbarUpdater14.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe [2013-02-18 968880]
S2 Web Assistant;Web Assistant;c:\program files\Web Assistant\ExtensionUpdaterService.exe [2013-01-29 188760]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-12-10 127328]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776]
S3 yukonw7;Ovladač NDIS6.2 Miniport pro řadič Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 17:19 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-07 10:30]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-07 20:07]
.
2013-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-07 20:07]
.
.
--------- X64 Entries -----------
.
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.iminent.com/?appId=156EE4 ... 572564C2E1
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000&st=18&barid={CFD61237-4204-11E1-AFF4-0016E656F306}
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://downloads.phpnuke.org/en/index.p ... gle&q={searchTerms}
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Search the Web - c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files (x86)\SpecialSavings\SpecialSavingsSinged.dll
TCP: DhcpNameServer = 192.168.0.1
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} -
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll
FF - ProfilePath - c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.search.selectedengine - search the web (babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT27866 ... hSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.as ... M=UM_ID&q=
FF - prefs.js: keyword.url - hxxp://search.conduit.com/resultsext.as ... ource=2&q=
FF - ExtSQL: 2013-03-01 07:15; {FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}; c:\program files\Web Assistant\Firefox
FF - ExtSQL: 2013-03-30 17:52; toolbar_SGT-V6@apn.ask.com; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\toolbar_SGT-V6@apn.ask.com.xpi
FF - ExtSQL: 2013-03-30 19:40; toolbar_SGT-SAT@apn.ask.com; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\toolbar_SGT-SAT@apn.ask.com.xpi
FF - ExtSQL: 2013-03-30 19:45; {ea614400-e918-4741-9a97-7a972ff7c30b}; c:\users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\3f0othnp.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{00cbb66b-1d3b-46d3-9577-323a336acb50} - c:\program files (x86)\BrowserCompanion\jsloader.dll
BHO-{0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - c:\program files (x86)\BFlix\BFlix.dll
BHO-{2863E737-DD3F-4280-9AF8-E9E79C16F312} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\MinBHO.dll
BHO-{72A1C27E-EBB0-789B-470D-4036B4F3C806} - c:\programdata\ADDICT-THING\bhoclass.dll
BHO-{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - c:\progra~2\Funmoods\1.5.23.22\bh\escort.dll
BHO-{99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
BHO-{B1D66BF3-1604-1F8A-A920-B4C0350367E0} - c:\programdata\ADDICT-THING\bhoclass.dll
BHO-{D7BE8ED1-B138-48FD-BB22-9779A39130B1} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SearchBHO.dll
Toolbar-10 - (no file)
Toolbar-{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - c:\progra~2\Funmoods\1.5.23.22\escorTlbr.dll
Toolbar-{99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
Toolbar-{3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - c:\program files (x86)\GadgetBox\gadgetBoxTB.dll
Toolbar-{F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\SaveTubeVideo.dll
Wow6432Node-HKLM-Run-Browser companion helper - c:\program files (x86)\BrowserCompanion\BCHelper.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
BHO-{336D0C35-8A85-403a-B9D2-65C292C39087} - (no file)
Toolbar-10 - (no file)
WebBrowser-{91397D20-1446-11D4-8AF4-0040CA1127B6} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
WebBrowser-{5347542D-5636-006A-76A7-7A786E7484D7} - (no file)
WebBrowser-{5347542D-5341-5400-76A7-7A786E7484D7} - (no file)
AddRemove-BrowserCompanion - c:\program files (x86)\BrowserCompanion\uninstall.exe
AddRemove-funmoods - c:\progra~2\Funmoods\1.5.23.22\uninstall.exe
AddRemove-SaveTubeVideo_is1 - c:\program files (x86)\SaveTubeVideo.com\SaveTubeVideo\unins000.exe
AddRemove-{71277DC4-4217-462A-9FF4-62D7815B2C69} - c:\programdata\ADDICT-THING\uninstall.exe
AddRemove-{d08d9f98-1c78-4704-87e6-368b0023d831} - c:\program files (x86)\RelevantKnowledge\rlvknlg.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va005]
"ImagePath"="\??\c:\users\Petr\AppData\Local\Temp\0054A13.tmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va011]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va011"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-243381793-2137855970-1547821832-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\progra~2\ICQ6TO~1\ICQSER~1.EXE
c:\program files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
c:\windows\SysWOW64\IoctlSvc.exe
c:\windows\SysWOW64\jmdp\stij.exe
.
**************************************************************************
.
Celkový čas: 2013-04-12 20:43:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-04-12 18:43
.
Před spuštěním: Volných bajtů: 60 246 585 344
Po spuštění: Volných bajtů: 59 986 239 488
.
- - End Of File - - B9D278ED29D13A243E8F0D4ADBCFDAAE