Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

HKU\S-1-5-21

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Swukle
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 lis 2015 20:39

Re: HKU\S-1-5-21

#16 Příspěvek od Swukle »

Tu je log z Zoek.exe
:

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by test on Łt 13.06.2017 at 18:51:41,80.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\test\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

13.6.2017 18:53:06 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Hotson deleted successfully
C:\PROGRA~2\UvConverter deleted successfully
C:\Program Files\paint.net deleted successfully
C:\Program Files\Unity deleted successfully
C:\PROGRA~3\Gaijin deleted successfully
C:\PROGRA~3\WinZip deleted successfully
C:\Users\test\AppData\Roaming\dvdcss deleted successfully
C:\Users\test\AppData\Roaming\Mozilla deleted successfully
C:\Users\test\AppData\Local\Doctor Entertainment AB deleted successfully
C:\Users\test\AppData\Local\fupdate deleted successfully
C:\Users\test\AppData\Local\MyComGames deleted successfully
C:\Users\test\AppData\Local\Opera Software deleted successfully
C:\Users\test\AppData\Local\Skype deleted successfully
C:\Users\test\AppData\Local\Unity deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00C77122-CC51-40BC-8827-713A67C673FE} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{02C948D1-7FFB-4398-B155-2FA91A8567A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03A5CF13-43AF-48F5-B86B-FF28E6868E87} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03F559D6-020F-4534-92E9-392C6E2B6318} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0DCA942C-8A28-42C2-9009-13E32A0E305C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0E556BF1-711E-438E-8CF8-71DAED6991C8} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{119665BD-4FF5-4D57-9758-A7141D4F3A9C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{15222496-FDF2-48CA-82DC-55AD5AACAF19} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{199C28E9-8413-4939-A7A8-71EF9506218F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2473AF8B-FD60-4BD7-BB36-0D3AD066ABED} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{24C92D3F-22FD-4EED-9C0C-E6489BE7288F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E3BC2D3-945A-4F85-A5BA-7A25F5786510} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2FDC5872-B839-4C94-8A9B-BF6CBAE5E53E} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{374A93A1-EDB5-4431-A477-B4C72EBF4308} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3A6E0DE6-59CE-4189-8EB1-CB242032A6F4} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AF713E1-FFFD-4E45-B485-FCB780A46033} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{405E21B8-8886-44EF-A35E-BDD0D3620055} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{467046C7-4F30-46E2-8964-B0576C0F2B22} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4CAA761E-A7C3-4D95-B98C-18D4EF4061FB} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{653BDE5B-218D-4AB6-96C2-59381D7CF215} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66B55641-2ADA-4829-B66B-A4784D35CA6D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6860ABFF-F9B1-4C71-AC39-D791AC7DF0B3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E072CB7-4213-4E18-9C62-E060062836E6} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70DC5876-E6AD-4395-BBA0-1AEB4582C00A} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{739A3952-4706-4878-80E7-F38C9ADC02D5} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78C852D1-06F4-44C2-A890-401B9A780002} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{791563B9-D882-4E25-9C2E-EEEF614C055C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E0A33FF-B04B-4509-9DB5-356586986347} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83F78B2E-0AE6-4BD6-95D6-40E8D3B5C49F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{844CC46B-80E4-4C7B-8101-DC0672EC893C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{854E70C7-D660-4C0A-87BF-E8FCEEBE4216} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88E041C2-7055-4381-94CB-7096A355700B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AA53924-5047-45F1-9C40-43A7B7FDA821} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EFDBF50-BAC4-4A53-8EAD-7B25676A8B0B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A1F0680-1F8E-4BF0-8813-23D978A9F704} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9AE6F83A-06D7-48D5-809B-628D04CC7A05} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EDE7CDC-9B92-4ED6-8D29-4B09DB3AE491} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A02FF799-55E7-49E0-94CC-A439F297346D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A1CC2FB6-7C3F-4CD2-A287-58AE7F9FB71D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4EA97CC-F476-4510-AAA1-03994E78D961} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B150FF15-7C28-482C-BAA6-645A8080A0A3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3FBFCAC-56BB-44FF-8BDC-CF8C4FA31AB8} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD1B0E51-11A1-4A4B-9E62-8C3C9E902721} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE7950B5-E101-44B8-9330-93883B868C4B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF1FF83-D72B-46DC-AC26-DEE8D1BD8B3F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C22523CD-3879-4EA5-AE6C-27CF1C837EA3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAB07409-F6E6-465D-B8B9-A8F550E6811B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D519532B-D975-40E6-BFD1-FF615DF7FA79} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA4FEB2A-976C-4C30-93E3-8B9AFEBD95A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB6CC53B-DA05-4038-B892-8DEEC1EFB018} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD0D9E16-6E61-418D-A609-36AABDCE4FF5} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD74EDE0-9344-40D2-B177-492A5633E0EE} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E04E036A-7FCA-42E3-BF26-C05527B6B417} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBE5A40A-DBC4-4FF9-AFEB-AF39803B3A61} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDAC9BDE-41A3-4701-9963-80F75D9854F7} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5E12CF7-AF1F-4A60-A4DB-C0CD5F5A7B2E} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE3ABB82-54E8-40AC-9AAB-F11160976380} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF90B044-721A-422C-B16B-E613E500322D} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OnfatDL deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\OnfatDL deleted successfully

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Hotson not found
C:\PROGRA~2\UvConverter not found
"C:\Windows\Installer\42888.msi" not found
C:\Users\test\AppData\Roaming\discord deleted
C:\Users\test\AppData\Local\AVG Web TuneUp deleted
C:\Users\test\.android deleted
C:\PROGRA~3\AVG Web TuneUp deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\test\AppData\LocalLow\Unity deleted
C:\Windows\Syswow64\5670.tmp deleted
C:\Windows\Syswow64\wsxBF8B.tmp deleted
C:\Users\test\AppData\Local\MSGBOX.EXE deleted
"C:\Users\test\AppData\Local\{63A790B6-F334-45F9-9095-128C623918F1}" deleted
"C:\Users\test\AppData\Local\{F856788D-C450-4BD4-941B-5EE325C0A541}" deleted
"C:\ProgramData\mntemp" deleted
"C:\ProgramData\XML" deleted
"C:\Users\test\AppData\Roaming\.technic" deleted
"C:\Users\test\AppData\Roaming\7DaysToDie" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted
"C:\Users\test\AppData\Local\CrashRpt" deleted

==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Default\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
ccfifbojenkenpkmnbnndeadpfdiffof - No path found[]
efaidnbmnnnibpcajpcglclefindmkaj - No path found[]
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]
gomekmidlodglbbmalcneegieacbdmki - No path found[]
oelpkepjlgmehajehfeicfbjdiobdkfj - No path found[]
ojlcebdkbpjdpiligkdbbkdkfjmchbfd - No path found[]
peefembmkccmkodbcpgilfjgkligpbba - No path found[]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
fcfenmboojpjinhpgggodefccipikbpd - No path found[]

Chrome Media Router - test\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Avast SafePrice - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Media Router - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Chrome Adr - test\AppData\Local\Hotson\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik
Tampermonkey - test\AppData\Local\Hotson\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
Chrome Media Router - test\AppData\Local\Hotson\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Avast SafePrice - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Media Router - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Chromium Fix ======================

C:\Users\test\AppData\Local\Hotson\User Data\Default\Local Storage\http_static.brazzers.com_0.localstorage deleted successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Local Storage\http_static.brazzers.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} Seznam Url="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
{3BF1670B-0D8A-4E20-B24B-CFD61F757B1A} (www.google.com) Google Url="http://www.google.com/search?q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}"
{9F976E67-9D9C-4F2B-BB92-BE375CC328CA} (www.google.com) Google Url="http://www.google.com/search?q={searchTerms}"
{C0C85594-B862-4570-848F-E85A0AB6DD3A} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"
{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="https://www.google.com/search?bcutc=sp- ... earchTerms}"

==== Reset Google Chrome ======================

C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal will be reset at reboot
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Web Data-journal was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Web Data-journal was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\test\Desktop\IdleMaster.exe – zástupce.lnk -
C:\Users\test\Desktop\ROBLOX Player.lnk - C:\Program Files (x86)\Roblox\Versions\version-bff08e723f284a81\RobloxPlayerLauncher.exe -browser
C:\Users\test\Desktop\ROBLOX Studio.lnk - C:\Program Files (x86)\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\test\Desktop\µTorrent.lnk -
C:\Users\test\Desktop\Errorz\Skype.lnk - C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe
C:\Users\test\Desktop\gud gejmz\Totally Accurate Battle Simulator.lnk - C:\Program Files (x86)\Totally Accurate Battle Simulator\TotallyAccurateBattleSimulator.exe
C:\Users\test\Desktop\Introbanner making\Koš – zástupce.lnk -
C:\Users\test\Desktop\Norml gejms\Counter-Strike.lnk - C:\Users\test\Counter-Strike 1.6\Counter-Strike.exe
C:\Users\test\Desktop\Norml gejms\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe
C:\Users\test\Desktop\Norml gejms\League of Legends.lnk - C:\Riot Games\League of Legends\lol.launcher.exe
C:\Users\test\Desktop\Norml gejms\Minecraft.lnk - C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
C:\Users\test\Desktop\Norml gejms\Pixelmon Launcher.lnk - C:\Program Files (x86)\Pixelmon Launcher (Beta)\PixelmonLauncher.exe
C:\Users\test\Desktop\Norml gejms\PokeCraft GameTeam 1.7.10.lnk - C:\GameTeamPokeCraft\PokeCraft GameTeam.jar PokeCraft GameTeam 1.7.10
C:\Users\test\Desktop\Norml gejms\ROBLOX Player.lnk - C:\Users\test\AppData\Local\Roblox\Versions\version-14d50132362e4612\RobloxPlayerLauncher.exe -browser
C:\Users\test\Desktop\Norml gejms\ROBLOX Studio.lnk - C:\Users\test\AppData\Local\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\Desktop\Norml gejms\SUPERHOT.lnk - C:\GOG Games\SUPERHOT\SUPERHOT.exe
C:\Users\test\Desktop\Norml gejms\WarThunder.lnk - C:\WarThunder\launcher.exe
C:\Users\test\Desktop\Norml gejms\World of Tanks - Common Test.lnk - C:\Games\World_of_Tanks_CT\WoTLauncher.exe
C:\Users\test\Desktop\Norml gejms\World of Tanks.lnk - C:\Games\World_of_Tanks\WoTLauncher.exe
C:\Users\test\Desktop\Norml gejms\World of Warships.lnk - C:\Games\World_of_Warships\WoWSLauncher.exe
C:\Users\test\Desktop\photos\fcNrIl.jpg – zástupce.lnk -
C:\Users\test\Desktop\stuf idk\Acrobat Reader DC.lnk - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
C:\Users\test\Desktop\stuf idk\ASRock OC Tuner.lnk - C:\Program Files (x86)\ASRock Utility\OCTuner\ASROC.exe
C:\Users\test\Desktop\stuf idk\ASRock XFast RAM.lnk - C:\Program Files\ASRock Utility\XFast RAM\XFastRAM.exe
C:\Users\test\Desktop\stuf idk\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\Users\test\Desktop\stuf idk\Cheat Engine.lnk - C:\Program Files (x86)\Cheat Engine 6.6\Cheat Engine.exe
C:\Users\test\Desktop\stuf idk\CPUID CPU-Z OC Formula.lnk - C:\Program Files\CPUID\CPU-Z ASR\cpuz.exe
C:\Users\test\Desktop\stuf idk\DAEMON Tools Lite.lnk - C:\Program Files\DAEMON Tools Lite\DTLauncher.exe
C:\Users\test\Desktop\stuf idk\GeForce Experience.lnk - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe
C:\Users\test\Desktop\stuf idk\HD VDeck.lnk - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Avast Koupený Antivirus.lnk -
C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\Users\Public\Desktop\Heroes of the Storm.lnk - C:\Program Files (x86)\Heroes of the Storm\Heroes of the Storm.exe
C:\Users\Public\Desktop\Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\Users\Public\Desktop\Overwatch Test.lnk - C:\Program Files (x86)\Overwatch Test\Overwatch Launcher.exe
C:\Users\Public\Desktop\Overwatch.lnk - C:\Program Files (x86)\Overwatch\Overwatch Launcher.exe
C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}\SkypeIcon.exe
C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Users Start Menu ======================

C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk - C:\Users\test\Desktop\Tor Browser\Browser\firefox.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Counter-Strike 1.6.lnk - C:\Counter-Strike 1.6\cskolauncher.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Half-Life.lnk - C:\Counter-Strike 1.6\cskolauncher.exe hl
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Odinstalovat Counter-Strike 1.6.lnk - C:\Counter-Strike 1.6\unins000.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Studio.lnk - C:\Users\test\AppData\Local\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Fórum podpory.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Složka nastavení.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Uninstall.lnk - C:\Users\test\AppData\Roaming\uTorrent\uninstall.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\µTorrent.lnk -

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm\Heroes of the Storm.lnk - C:\Program Files (x86)\Heroes of the Storm\Heroes of the Storm.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Uninstall Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk - C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch\Overwatch.lnk - C:\Program Files (x86)\Overwatch\Overwatch Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch Test\Overwatch Test.lnk - C:\Program Files (x86)\Overwatch Test\Overwatch Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Player.lnk - C:\Program Files (x86)\Roblox\Versions\version-bff08e723f284a81\RobloxPlayerLauncher.exe -browser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Studio.lnk - C:\Program Files (x86)\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Amigo.lnk - C:\Users\test\AppData\Local\Amigo\Application\amigo.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - C:\Windows\System32\rundll32.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\?????????.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\?????????????.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\70f62c6a7f1739bd\pinned.lnk - C:\Windows\system32\rundll32.exe C:\Windows\system32\shell32.dll,Options_RunDLL 1
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7dc2e4d4ae6cc8f4\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe --profile-directory=qudachmupishplalily
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\81f60f1222210b45\League of Legends.lnk - C:\Riot Games\League of Legends\LeagueClient.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\b5886302bba62f78\League of Legends.lnk - C:\Users\test\APPDATA\LOCAL\TEMP\Rar$EXa0.803\PBE\lol.launcher.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\chrome.exe – zástupce.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Správce úloh systému Windows.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\?oo?le ?hro?e.lnk -

==== shortcuts After Repair ======================

C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Amigo.lnk - C:\Users\test\AppData\Local\Amigo\Application\amigo.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Clownfish deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8M4F9H will be deleted at reboot
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BU6HI34J will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache will be emptied at reboot
C:\Users\test\AppData\Local\Hotson\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6184 folders=920 1067099533 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\test\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\test\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal" not found
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index" deleted
"C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8M4F9H" not found
"C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BU6HI34J" not found

==== EOF on Łt 13.06.2017 at 19:40:19,41 ======================

Swukle
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 lis 2015 20:39

Re: HKU\S-1-5-21

#17 Příspěvek od Swukle »

Tu je log z Zoek.exe
:

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by test on Łt 13.06.2017 at 18:51:41,80.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\test\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

13.6.2017 18:53:06 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Hotson deleted successfully
C:\PROGRA~2\UvConverter deleted successfully
C:\Program Files\paint.net deleted successfully
C:\Program Files\Unity deleted successfully
C:\PROGRA~3\Gaijin deleted successfully
C:\PROGRA~3\WinZip deleted successfully
C:\Users\test\AppData\Roaming\dvdcss deleted successfully
C:\Users\test\AppData\Roaming\Mozilla deleted successfully
C:\Users\test\AppData\Local\Doctor Entertainment AB deleted successfully
C:\Users\test\AppData\Local\fupdate deleted successfully
C:\Users\test\AppData\Local\MyComGames deleted successfully
C:\Users\test\AppData\Local\Opera Software deleted successfully
C:\Users\test\AppData\Local\Skype deleted successfully
C:\Users\test\AppData\Local\Unity deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00C77122-CC51-40BC-8827-713A67C673FE} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{02C948D1-7FFB-4398-B155-2FA91A8567A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03A5CF13-43AF-48F5-B86B-FF28E6868E87} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{03F559D6-020F-4534-92E9-392C6E2B6318} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0DCA942C-8A28-42C2-9009-13E32A0E305C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0E556BF1-711E-438E-8CF8-71DAED6991C8} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{119665BD-4FF5-4D57-9758-A7141D4F3A9C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{15222496-FDF2-48CA-82DC-55AD5AACAF19} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{199C28E9-8413-4939-A7A8-71EF9506218F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2473AF8B-FD60-4BD7-BB36-0D3AD066ABED} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{24C92D3F-22FD-4EED-9C0C-E6489BE7288F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2E3BC2D3-945A-4F85-A5BA-7A25F5786510} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2FDC5872-B839-4C94-8A9B-BF6CBAE5E53E} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{374A93A1-EDB5-4431-A477-B4C72EBF4308} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3A6E0DE6-59CE-4189-8EB1-CB242032A6F4} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AF713E1-FFFD-4E45-B485-FCB780A46033} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{405E21B8-8886-44EF-A35E-BDD0D3620055} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{467046C7-4F30-46E2-8964-B0576C0F2B22} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4CAA761E-A7C3-4D95-B98C-18D4EF4061FB} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{653BDE5B-218D-4AB6-96C2-59381D7CF215} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{66B55641-2ADA-4829-B66B-A4784D35CA6D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6860ABFF-F9B1-4C71-AC39-D791AC7DF0B3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E072CB7-4213-4E18-9C62-E060062836E6} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{70DC5876-E6AD-4395-BBA0-1AEB4582C00A} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{739A3952-4706-4878-80E7-F38C9ADC02D5} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78C852D1-06F4-44C2-A890-401B9A780002} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{791563B9-D882-4E25-9C2E-EEEF614C055C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E0A33FF-B04B-4509-9DB5-356586986347} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83F78B2E-0AE6-4BD6-95D6-40E8D3B5C49F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{844CC46B-80E4-4C7B-8101-DC0672EC893C} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{854E70C7-D660-4C0A-87BF-E8FCEEBE4216} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88E041C2-7055-4381-94CB-7096A355700B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8AA53924-5047-45F1-9C40-43A7B7FDA821} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EFDBF50-BAC4-4A53-8EAD-7B25676A8B0B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9A1F0680-1F8E-4BF0-8813-23D978A9F704} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9AE6F83A-06D7-48D5-809B-628D04CC7A05} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EDE7CDC-9B92-4ED6-8D29-4B09DB3AE491} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A02FF799-55E7-49E0-94CC-A439F297346D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A1CC2FB6-7C3F-4CD2-A287-58AE7F9FB71D} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4EA97CC-F476-4510-AAA1-03994E78D961} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B150FF15-7C28-482C-BAA6-645A8080A0A3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3FBFCAC-56BB-44FF-8BDC-CF8C4FA31AB8} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BD1B0E51-11A1-4A4B-9E62-8C3C9E902721} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE7950B5-E101-44B8-9330-93883B868C4B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF1FF83-D72B-46DC-AC26-DEE8D1BD8B3F} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C22523CD-3879-4EA5-AE6C-27CF1C837EA3} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAB07409-F6E6-465D-B8B9-A8F550E6811B} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D519532B-D975-40E6-BFD1-FF615DF7FA79} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DA4FEB2A-976C-4C30-93E3-8B9AFEBD95A9} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB6CC53B-DA05-4038-B892-8DEEC1EFB018} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD0D9E16-6E61-418D-A609-36AABDCE4FF5} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD74EDE0-9344-40D2-B177-492A5633E0EE} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E04E036A-7FCA-42E3-BF26-C05527B6B417} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EBE5A40A-DBC4-4FF9-AFEB-AF39803B3A61} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDAC9BDE-41A3-4701-9963-80F75D9854F7} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F5E12CF7-AF1F-4A60-A4DB-C0CD5F5A7B2E} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE3ABB82-54E8-40AC-9AAB-F11160976380} deleted successfully
HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF90B044-721A-422C-B16B-E613E500322D} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1906927588-4285542165-1585533686-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OnfatDL deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\OnfatDL deleted successfully

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Hotson not found
C:\PROGRA~2\UvConverter not found
"C:\Windows\Installer\42888.msi" not found
C:\Users\test\AppData\Roaming\discord deleted
C:\Users\test\AppData\Local\AVG Web TuneUp deleted
C:\Users\test\.android deleted
C:\PROGRA~3\AVG Web TuneUp deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\test\AppData\LocalLow\Unity deleted
C:\Windows\Syswow64\5670.tmp deleted
C:\Windows\Syswow64\wsxBF8B.tmp deleted
C:\Users\test\AppData\Local\MSGBOX.EXE deleted
"C:\Users\test\AppData\Local\{63A790B6-F334-45F9-9095-128C623918F1}" deleted
"C:\Users\test\AppData\Local\{F856788D-C450-4BD4-941B-5EE325C0A541}" deleted
"C:\ProgramData\mntemp" deleted
"C:\ProgramData\XML" deleted
"C:\Users\test\AppData\Roaming\.technic" deleted
"C:\Users\test\AppData\Roaming\7DaysToDie" deleted
"C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted
"C:\Users\test\AppData\Local\CrashRpt" deleted

==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Default\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
ccfifbojenkenpkmnbnndeadpfdiffof - No path found[]
efaidnbmnnnibpcajpcglclefindmkaj - No path found[]
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]
gomekmidlodglbbmalcneegieacbdmki - No path found[]
oelpkepjlgmehajehfeicfbjdiobdkfj - No path found[]
ojlcebdkbpjdpiligkdbbkdkfjmchbfd - No path found[]
peefembmkccmkodbcpgilfjgkligpbba - No path found[]

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
fcfenmboojpjinhpgggodefccipikbpd - No path found[]

Chrome Media Router - test\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Avast SafePrice - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Media Router - test\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Chrome Adr - test\AppData\Local\Hotson\User Data\Default\Extensions\bpiopmneeadfapifejkfpahpljkicpik
Tampermonkey - test\AppData\Local\Hotson\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
Chrome Media Router - test\AppData\Local\Hotson\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Avast SafePrice - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Media Router - test\AppData\Local\Hotson\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Chromium Fix ======================

C:\Users\test\AppData\Local\Hotson\User Data\Default\Local Storage\http_static.brazzers.com_0.localstorage deleted successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Local Storage\http_static.brazzers.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.com/?bcutc=sp-006"
"Search Page"="https://www.google.com/search?bcutc=sp- ... earchTerms}"
"Search Bar"="https://www.google.com/?bcutc=sp-006"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.google.com/?bcutc=sp-006"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} Seznam Url="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
{3BF1670B-0D8A-4E20-B24B-CFD61F757B1A} (www.google.com) Google Url="http://www.google.com/search?q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}"
{9F976E67-9D9C-4F2B-BB92-BE375CC328CA} (www.google.com) Google Url="http://www.google.com/search?q={searchTerms}"
{C0C85594-B862-4570-848F-E85A0AB6DD3A} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"
{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="https://www.google.com/search?bcutc=sp- ... earchTerms}"

==== Reset Google Chrome ======================

C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Preferences was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data will be reset at reboot
C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal will be reset at reboot
C:\Users\test\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Default\Web Data-journal was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Web Data was reset successfully
C:\Users\test\AppData\Local\Hotson\User Data\Profile 1\Web Data-journal was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\test\Desktop\IdleMaster.exe – zástupce.lnk -
C:\Users\test\Desktop\ROBLOX Player.lnk - C:\Program Files (x86)\Roblox\Versions\version-bff08e723f284a81\RobloxPlayerLauncher.exe -browser
C:\Users\test\Desktop\ROBLOX Studio.lnk - C:\Program Files (x86)\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\test\Desktop\µTorrent.lnk -
C:\Users\test\Desktop\Errorz\Skype.lnk - C:\Windows\Installer\{FC965A47-4839-40CA-B618-18F486F042C6}\SkypeIcon.exe
C:\Users\test\Desktop\gud gejmz\Totally Accurate Battle Simulator.lnk - C:\Program Files (x86)\Totally Accurate Battle Simulator\TotallyAccurateBattleSimulator.exe
C:\Users\test\Desktop\Introbanner making\Koš – zástupce.lnk -
C:\Users\test\Desktop\Norml gejms\Counter-Strike.lnk - C:\Users\test\Counter-Strike 1.6\Counter-Strike.exe
C:\Users\test\Desktop\Norml gejms\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe
C:\Users\test\Desktop\Norml gejms\League of Legends.lnk - C:\Riot Games\League of Legends\lol.launcher.exe
C:\Users\test\Desktop\Norml gejms\Minecraft.lnk - C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
C:\Users\test\Desktop\Norml gejms\Pixelmon Launcher.lnk - C:\Program Files (x86)\Pixelmon Launcher (Beta)\PixelmonLauncher.exe
C:\Users\test\Desktop\Norml gejms\PokeCraft GameTeam 1.7.10.lnk - C:\GameTeamPokeCraft\PokeCraft GameTeam.jar PokeCraft GameTeam 1.7.10
C:\Users\test\Desktop\Norml gejms\ROBLOX Player.lnk - C:\Users\test\AppData\Local\Roblox\Versions\version-14d50132362e4612\RobloxPlayerLauncher.exe -browser
C:\Users\test\Desktop\Norml gejms\ROBLOX Studio.lnk - C:\Users\test\AppData\Local\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\Desktop\Norml gejms\SUPERHOT.lnk - C:\GOG Games\SUPERHOT\SUPERHOT.exe
C:\Users\test\Desktop\Norml gejms\WarThunder.lnk - C:\WarThunder\launcher.exe
C:\Users\test\Desktop\Norml gejms\World of Tanks - Common Test.lnk - C:\Games\World_of_Tanks_CT\WoTLauncher.exe
C:\Users\test\Desktop\Norml gejms\World of Tanks.lnk - C:\Games\World_of_Tanks\WoTLauncher.exe
C:\Users\test\Desktop\Norml gejms\World of Warships.lnk - C:\Games\World_of_Warships\WoWSLauncher.exe
C:\Users\test\Desktop\photos\fcNrIl.jpg – zástupce.lnk -
C:\Users\test\Desktop\stuf idk\Acrobat Reader DC.lnk - C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
C:\Users\test\Desktop\stuf idk\ASRock OC Tuner.lnk - C:\Program Files (x86)\ASRock Utility\OCTuner\ASROC.exe
C:\Users\test\Desktop\stuf idk\ASRock XFast RAM.lnk - C:\Program Files\ASRock Utility\XFast RAM\XFastRAM.exe
C:\Users\test\Desktop\stuf idk\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\Users\test\Desktop\stuf idk\Cheat Engine.lnk - C:\Program Files (x86)\Cheat Engine 6.6\Cheat Engine.exe
C:\Users\test\Desktop\stuf idk\CPUID CPU-Z OC Formula.lnk - C:\Program Files\CPUID\CPU-Z ASR\cpuz.exe
C:\Users\test\Desktop\stuf idk\DAEMON Tools Lite.lnk - C:\Program Files\DAEMON Tools Lite\DTLauncher.exe
C:\Users\test\Desktop\stuf idk\GeForce Experience.lnk - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\LaunchGFExperience.exe
C:\Users\test\Desktop\stuf idk\HD VDeck.lnk - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Avast Koupený Antivirus.lnk -
C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\Users\Public\Desktop\Heroes of the Storm.lnk - C:\Program Files (x86)\Heroes of the Storm\Heroes of the Storm.exe
C:\Users\Public\Desktop\Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\Users\Public\Desktop\Overwatch Test.lnk - C:\Program Files (x86)\Overwatch Test\Overwatch Launcher.exe
C:\Users\Public\Desktop\Overwatch.lnk - C:\Program Files (x86)\Overwatch\Overwatch Launcher.exe
C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}\SkypeIcon.exe
C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Users Start Menu ======================

C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk - C:\Users\test\Desktop\Tor Browser\Browser\firefox.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Counter-Strike 1.6.lnk - C:\Counter-Strike 1.6\cskolauncher.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Half-Life.lnk - C:\Counter-Strike 1.6\cskolauncher.exe hl
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6\Odinstalovat Counter-Strike 1.6.lnk - C:\Counter-Strike 1.6\unins000.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Studio.lnk - C:\Users\test\AppData\Local\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Fórum podpory.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Složka nastavení.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\Uninstall.lnk - C:\Users\test\AppData\Roaming\uTorrent\uninstall.exe
C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent\µTorrent.lnk -

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm\Heroes of the Storm.lnk - C:\Program Files (x86)\Heroes of the Storm\Heroes of the Storm.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Uninstall Malwarebytes.lnk - C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk - C:\Program Files (x86)\Minecraft\MinecraftLauncher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch\Overwatch.lnk - C:\Program Files (x86)\Overwatch\Overwatch Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch Test\Overwatch Test.lnk - C:\Program Files (x86)\Overwatch Test\Overwatch Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Player.lnk - C:\Program Files (x86)\Roblox\Versions\version-bff08e723f284a81\RobloxPlayerLauncher.exe -browser
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox\ROBLOX Studio.lnk - C:\Program Files (x86)\Roblox\Versions\RobloxStudioLauncherBeta.exe -ide
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Amigo.lnk - C:\Users\test\AppData\Local\Amigo\Application\amigo.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe https://launchpage.org/?uid=oTlKBKjdhx0 ... %2BoLCk%3D
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk - C:\Windows\System32\rundll32.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\?????????.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\?????????????.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\70f62c6a7f1739bd\pinned.lnk - C:\Windows\system32\rundll32.exe C:\Windows\system32\shell32.dll,Options_RunDLL 1
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7dc2e4d4ae6cc8f4\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe --profile-directory=qudachmupishplalily
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\81f60f1222210b45\League of Legends.lnk - C:\Riot Games\League of Legends\LeagueClient.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\b5886302bba62f78\League of Legends.lnk - C:\Users\test\APPDATA\LOCAL\TEMP\Rar$EXa0.803\PBE\lol.launcher.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\chrome.exe – zástupce.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Správce úloh systému Windows.lnk -
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\?oo?le ?hro?e.lnk -

==== shortcuts After Repair ======================

C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Amigo.lnk - C:\Users\test\AppData\Local\Amigo\Application\amigo.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk - C:\Program Files\AVAST Software\SZBrowser\launcher.exe
C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Hotson\Application\chrome.exe

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F39E5917C417B4041A46F88010121C6E deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F39E5917C417B4041A46F88010121C6E deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Clownfish deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8M4F9H will be deleted at reboot
C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BU6HI34J will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache will be emptied at reboot
C:\Users\test\AppData\Local\Hotson\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6184 folders=920 1067099533 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\test\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\test\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data" not found
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal" not found
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3" deleted
"C:\Users\test\AppData\Local\Google\Chrome\User Data\Default\Cache\index" deleted
"C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8M4F9H" not found
"C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BU6HI34J" not found

==== EOF on Łt 13.06.2017 at 19:40:19,41 ======================

Swukle
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 lis 2015 20:39

Re: HKU\S-1-5-21

#18 Příspěvek od Swukle »

A tady je JUNKWARE REMOVAL TOOL Log


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Professional x64
Ran by test (Administrator) on Łt 13.06.2017 at 19:45:12,54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 15

Successfully deleted: C:\ProgramData\Start Menu\Programs\mpc desktop (Folder)
Successfully deleted: C:\Users\test\AppData\Local\nico mak computing (Folder)
Successfully deleted: C:\Users\test\AppData\Roaming\mailproducts (Folder)
Successfully deleted: C:\Users\test\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\amigo.lnk (Shortcut)
Successfully deleted: C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\amigo.lnk (Shortcut)
Successfully deleted: C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0RHYUAEF (Temporary Internet Files Folder)
Successfully deleted: C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RTDMN1F (Temporary Internet Files Folder)
Successfully deleted: C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6KR9J8WZ (Temporary Internet Files Folder)
Successfully deleted: C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWV27KBD (Temporary Internet Files Folder)
Successfully deleted: C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VWJ3MZ4Y (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0RHYUAEF (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RTDMN1F (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6KR9J8WZ (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EWV27KBD (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VWJ3MZ4Y (Temporary Internet Files Folder)



Registry: 3

Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\amigo (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 13.06.2017 at 19:48:55,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: HKU\S-1-5-21

#19 Příspěvek od Rudy »

Změnilo se něco nyní?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Swukle
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 lis 2015 20:39

Re: HKU\S-1-5-21

#20 Příspěvek od Swukle »

Odstranilo to hodně reklam , pár jich tu je a když něco vyhledám tak málokdy se to přesune úplně na jiný vyhledávač.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: HKU\S-1-5-21

#21 Příspěvek od Rudy »

Ještě zkuste ChromeCleanupTool: https://www.google.com/chrome/cleanup-tool/ .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Swukle
Návštěvník
Návštěvník
Příspěvky: 24
Registrován: 17 lis 2015 20:39

Re: HKU\S-1-5-21

#22 Příspěvek od Swukle »

Chrome clean up tool nenašel žádné programy, ale já stále mám reklamy

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: HKU\S-1-5-21

#23 Příspěvek od Rudy »

Tak holt přeinstalaci. Chrome zazálohujte pomocí ChromeBackup: http://www.stahuj.centrum.cz/internet_a ... me-backup/ . Poté chrome odinstalujte vč. jeho profilu (podadresáře Chrome v c:\users\test\appdata\local, c:\users\test\appdata\roaming, c:\users\test\data aplikací, c:\users\test\local settings a v c:\program data musí být smazány). Proveďte novou, čistou instalaci chrome a zpět ze zálohy nakopírujte pouze záložky a hesla.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět