Neznámé soubory ve složce uživatele
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému hned. Děkujeme za pochopení.
Neznámé soubory ve složce uživatele
Dobrý den.
Mám malý problém. Ve složce uživatel se mi furt objevují dva soubory : regbcm, rgmnr. Když je odstraním při dalším spuštění notebooku tam zase jsou. Když spustím antivirus Windows Defender tak mě nic nenajde. Možná o nic nejde ale mám strach, že by to mohlo vyvrcholit v něco horšího. Prosím poraďte mi co mám dělat. Děkuji.
Zde je log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by Uzivatel (administrator) on LENOVO on 15-04-2014 13:50:20
Running from C:\Users\Uzivatel\Downloads
Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\windows\system32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems Inc.) C:\windows\system32\CxAudMsg64.exe
(Microsoft Corporation) C:\windows\system32\dashost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(SkypEmoticons) C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons\SE.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(BitTorrent Inc.) C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
() C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\windows\inf\msciuejuw\msciuejuw.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
() C:\windows\inf\msmigqmk\msmigqmk.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Microsoft Corporation) C:\windows\syswow64\wwahost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2872720 2012-10-03] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-03-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-03-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [172144 2012-12-14] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [399984 2012-12-14] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [441968 2012-12-14] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [139792 2012-11-08] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-11-08] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [msksceqSrv] => C:\windows\inf\msksceq.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1801168 2014-04-05] (APN)
HKLM-x32\...\Run: [mstrjjSrv] => C:\windows\inf\mstrjj.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MSStp] => C:\windows\SysWOW64\msstp.vbe [1419 2014-01-19] ()
HKLM-x32\...\Run: [mncqrorcSrv] => C:\windows\inf\mncqrorc.vbe [1342 2014-01-19] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Google Update] => C:\Users\Uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-09] (Google Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [se] => C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons\SE.exe [5679008 2014-04-03] (SkypEmoticons)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [uTorrent] => C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-02-11] (BitTorrent Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Microsoft Application Manager] => C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe [193536 2014-03-26] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\MountPoints2: {65c2ff22-8c7a-11e2-be6b-806e6f6e6963} - "E:\Autorun.exe"
AppInit_DLLs: C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL => C:\Program Files (x86)\GS-Enabler\Browsafe_x64.dll [4581376 2013-12-27] ()
AppInit_DLLs-x32: c:\progra~2\gs-ena~1\browsafe.dll => C:\Program Files (x86)\GS-Enabler\Browsafe.dll [4370944 2013-12-27] ()
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registrationa1\RegistrationReminder.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registration\RegistrationReminder.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 33-115&t=4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
URLSearchHook: HKLM-x32 - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKCU - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM-x32 - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={search ... 3&tsp=4986
SearchScopes: HKCU - {164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKCU - {1BED6179-5314-4660-9C0A-CFFE4683E27E} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {23F84887-CA4F-4FD2-882A-EAE131127D23} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {32C87758-FF98-43A5-9F32-6C22364558E3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKCU - {475D1C03-1095-42B4-9EC4-06AC02B8127A} URL = http://search.conduit.com/ResultsExt.as ... 61163&UM=1
SearchScopes: HKCU - {5DFD4BF8-81DF-4AF6-871A-5F237F5CD584} URL = http://search.softonic.com/INF00176/tb_ ... d6e2&r=203
SearchScopes: HKCU - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL =
SearchScopes: HKCU - {6A0758B4-A0F2-49B7-965A-05FF41A44F3C} URL = http://search.aol.com/aol/search?s_it=t ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {B57B17D2-6231-42BB-99B8-FEDD49A69D59} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKCU - {C08DC435-369D-48F5-BA6C-B88F83EE3846} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKCU - {FBD1D3B1-12D6-4CE7-8985-752FE8303783} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
BHO: TubeItAdBlockAop - {375E1565-9EF3-250C-B3BC-5D802D2DDCFB} - C:\ProgramData\TubeItAdBlockAop\Ic9Wjo.x64.dll ()
BHO: RandoomPrice - {49C3E4B7-B33C-29D1-8441-9D7291DCE897} - C:\ProgramData\RandoomPrice\E3SwWBi.x64.dll ()
BHO: CoupEextensuIon - {57DA1AB4-B7A1-B09C-41B7-D44D368537D6} - C:\ProgramData\CoupEextensuIon\kTk__m4.x64.dll ()
BHO: SaveeRExtoeNsion - {7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} - C:\ProgramData\SaveeRExtoeNsion\s.x64.dll ()
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: TubeItAdBlockAop - {375E1565-9EF3-250C-B3BC-5D802D2DDCFB} - C:\ProgramData\TubeItAdBlockAop\Ic9Wjo.dll ()
BHO-x32: RandoomPrice - {49C3E4B7-B33C-29D1-8441-9D7291DCE897} - C:\ProgramData\RandoomPrice\E3SwWBi.dll ()
BHO-x32: CoupEextensuIon - {57DA1AB4-B7A1-B09C-41B7-D44D368537D6} - C:\ProgramData\CoupEextensuIon\kTk__m4.dll ()
BHO-x32: SaveeRExtoeNsion - {7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} - C:\ProgramData\SaveeRExtoeNsion\s.dll ()
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {96F454EA-9D38-474F-B504-56193E00C1A5} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: google
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a10733-115&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=7491911322904840&o=APN10645&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: RandoomPrice - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\ni3w60@oaqh-zlzd.edu [2014-03-08]
FF Extension: TubeItAdBlockAop - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\skf1_0tg@iy-kajfqo.org [2014-02-05]
FF Extension: SaveeRExtoeNsion - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\uuue.oy@zkqtapxoft.com [2014-01-01]
FF Extension: CoupEextensuIon - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\yee7qo@qkiuoy.co.uk [2014-01-01]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-29]
FF HKLM-x32\...\Firefox\Extensions: [7go@7go.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com
FF Extension: 7Go Games - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com [2013-08-26]
FF HKLM-x32\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-08-26]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [7go@7go.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com
FF Extension: 7Go Games - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com [2013-08-26]
FF HKCU\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-08-26]
Chrome:
=======
CHR HomePage: https://www.google.com/?hl=cs
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Intel\xC2\xAE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\xC2\xAE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Unity Player) - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Google Update) - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Extension: (Google Drive) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-26]
CHR Extension: (YouTube) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-26]
CHR Extension: (Google Search) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-26]
CHR Extension: (CoupEextensuIon) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf [2013-12-31]
CHR Extension: (RandoomPrice) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda [2014-03-07]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkobdpgofbmhpeaedbmgjcfcecmedgoa [2013-11-13]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpjompbfihdbjohiipgldnoocmlnfdae [2013-11-13]
CHR Extension: (Pen\xC4\x9B\xC5\xBEenka Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf [2013-12-27]
CHR Extension: (Gmail) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-26]
CHR Extension: (SaveeRExtoeNsion) - C:\ProgramData\odlcbfcjpeocknpekoimjlgimdpolpdf [2013-12-31]
CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-07-27]
CHR HKLM-x32\...\Chrome\Extension: [aaaaabcbmongicmdegkmmfgdickgnnob] - C:\Users\Uzivatel\AppData\Local\ilividmoviestoolbardla\GC\toolbar.crx [2013-06-12]
CHR HKLM-x32\...\Chrome\Extension: [aaaajpkhjdkhhnkmgfjodbkfpbmibkkk] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7\CRX\ToolbarCR.crx [2014-04-05]
CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-07-27]
CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonic.crx [2013-05-01]
CHR HKLM-x32\...\Chrome\Extension: [gjajpkikblccgefaibcafkfbanllpefi] - C:\Users\Uzivatel\AppData\Roaming\7go\7go.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Uzivatel\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-07-30]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-04-05] (APN LLC.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2012-10-02] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-16] (Broadcom Corporation.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 e81a9dc1; C:\Program Files (x86)\GS-Enabler\BrowsafeSvc.dll [180048 2013-12-27] ()
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [83968 2012-09-05] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2013-11-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-01-07] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2012-10-02] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-11-10] (Disc Soft Ltd)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-01-07] ()
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8222736 2012-06-15] (Realtek Semiconductor Corp.)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-15 13:50 - 2014-04-15 13:51 - 00030740 _____ () C:\Users\Uzivatel\Downloads\FRST.txt
2014-04-15 13:50 - 2014-04-15 13:50 - 00000000 ____D () C:\FRST
2014-04-15 13:47 - 2014-04-15 13:47 - 02054144 _____ (Farbar) C:\Users\Uzivatel\Downloads\FRST64.exe
2014-04-13 19:36 - 2014-04-13 19:35 - 00011331 _____ () C:\Users\Uzivatel\Downloads\DayZ-1.7.1.torrent
2014-04-13 16:49 - 2014-04-15 13:11 - 00012991 _____ () C:\Users\Uzivatel\rgmnr
2014-04-13 16:48 - 2014-04-13 16:48 - 00000000 _____ () C:\Users\Uzivatel\regbcm
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\PAYDAY 2
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\EMU
2014-04-13 12:46 - 2014-04-13 12:46 - 00001159 _____ () C:\Users\Public\Desktop\PAYDAY 2.lnk
2014-04-13 12:15 - 2014-04-13 12:46 - 00000000 ____D () C:\Program Files (x86)\PAYDAY 2
2014-04-13 08:21 - 2014-04-13 12:13 - 3942678528 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD2.iso
2014-04-12 22:01 - 2014-04-13 05:56 - 4246634496 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD1.iso
2014-04-08 06:57 - 2014-04-08 06:57 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Updater
2014-04-07 18:32 - 2014-04-07 18:32 - 00001041 _____ () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hádanka – zástupce.lnk
2014-04-07 18:17 - 2014-04-08 16:16 - 00000000 ___RD () C:\Users\Uzivatel\Desktop\Hry
2014-03-30 13:16 - 2014-03-30 13:17 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-03-30 12:52 - 2014-04-08 17:51 - 00000000 ____D () C:\Users\Uzivatel\Documents\StarCraft II
2014-03-30 12:52 - 2014-04-08 14:11 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-03-30 12:52 - 2014-03-30 13:14 - 00001104 _____ () C:\Users\Uzivatel\Desktop\StarCraft II.lnk
2014-03-30 11:50 - 2014-03-30 12:23 - 00000000 ____D () C:\Program Files (x86)\Warcraft II
2014-03-29 12:00 - 2014-03-29 12:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:38 - 2014-03-29 11:38 - 00000000 ____D () C:\Users\Uzivatel\Downloads\StarCraft.II.Wings.of.Liberty - RELOADED
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\Documents\Might & Magic Heroes VI
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Might & Magic Heroes VI
2014-03-27 14:41 - 2014-03-27 15:19 - 00000000 ____D () C:\Program Files (x86)\Might & Magic Heroes VI
2014-03-26 21:41 - 2014-03-26 21:43 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Ubisoft Game Launcher
2014-03-26 19:39 - 2014-03-26 19:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-03-23 19:11 - 2014-03-23 19:26 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\Documents\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\cache
2014-03-23 19:01 - 2014-03-23 19:01 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Cheat Tables
2014-03-21 22:35 - 2014-03-21 22:35 - 04930704 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 10:32 - 2014-03-23 19:01 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V - Tribes of the East
==================== One Month Modified Files and Folders =======
2014-04-15 13:51 - 2014-04-15 13:50 - 00030740 _____ () C:\Users\Uzivatel\Downloads\FRST.txt
2014-04-15 13:50 - 2014-04-15 13:50 - 00000000 ____D () C:\FRST
2014-04-15 13:50 - 2013-08-27 15:22 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\uTorrent
2014-04-15 13:47 - 2014-04-15 13:47 - 02054144 _____ (Farbar) C:\Users\Uzivatel\Downloads\FRST64.exe
2014-04-15 13:31 - 2013-09-21 16:59 - 01966644 _____ () C:\windows\WindowsUpdate.log
2014-04-15 13:19 - 2013-08-26 15:03 - 00000970 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-15 13:15 - 2013-07-12 09:09 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Seznam.cz
2014-04-15 13:14 - 2013-06-27 14:57 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-141415711-4277777738-1014465746-1002
2014-04-15 13:12 - 2013-03-14 10:37 - 00727488 _____ () C:\windows\system32\perfh005.dat
2014-04-15 13:12 - 2013-03-14 10:37 - 00148006 _____ () C:\windows\system32\perfc005.dat
2014-04-15 13:12 - 2012-07-26 09:28 - 01714430 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-15 13:11 - 2014-04-13 16:49 - 00012991 _____ () C:\Users\Uzivatel\rgmnr
2014-04-15 13:10 - 2013-06-27 14:51 - 00000000 ___RD () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-15 13:10 - 2013-06-27 14:49 - 00000000 ____D () C:\Users\Uzivatel
2014-04-15 13:09 - 2013-08-26 15:03 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 13:09 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-04-14 13:54 - 2013-07-09 17:15 - 00000988 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141415711-4277777738-1014465746-1002UA.job
2014-04-14 07:26 - 2013-08-29 07:54 - 00149504 ___SH () C:\Users\Uzivatel\Thumbs.db
2014-04-13 21:30 - 2013-07-09 17:15 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141415711-4277777738-1014465746-1002Core.job
2014-04-13 19:48 - 2013-07-18 13:23 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\DAEMON Tools Lite
2014-04-13 19:35 - 2014-04-13 19:36 - 00011331 _____ () C:\Users\Uzivatel\Downloads\DayZ-1.7.1.torrent
2014-04-13 16:48 - 2014-04-13 16:48 - 00000000 _____ () C:\Users\Uzivatel\regbcm
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\PAYDAY 2
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\EMU
2014-04-13 13:03 - 2013-09-21 15:19 - 00273436 _____ () C:\windows\DirectX.log
2014-04-13 12:46 - 2014-04-13 12:46 - 00001159 _____ () C:\Users\Public\Desktop\PAYDAY 2.lnk
2014-04-13 12:46 - 2014-04-13 12:15 - 00000000 ____D () C:\Program Files (x86)\PAYDAY 2
2014-04-13 12:13 - 2014-04-13 08:21 - 3942678528 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD2.iso
2014-04-13 05:56 - 2014-04-12 22:01 - 4246634496 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD1.iso
2014-04-11 18:28 - 2013-08-14 20:39 - 00000000 ____D () C:\windows\system32\MRT
2014-04-11 18:02 - 2013-06-27 15:43 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-10 20:17 - 2013-10-10 15:48 - 00015643 _____ () C:\windows\setupact.log
2014-04-10 20:02 - 2013-08-26 08:29 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\File Scout
2014-04-09 21:17 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-09 18:27 - 2013-07-09 12:53 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Skype
2014-04-09 18:26 - 2013-07-09 10:31 - 00000000 ____D () C:\Users\Uzivatel\Documents\Youcam
2014-04-08 21:26 - 2013-11-03 18:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Battle.net
2014-04-08 17:51 - 2014-03-30 12:52 - 00000000 ____D () C:\Users\Uzivatel\Documents\StarCraft II
2014-04-08 16:16 - 2014-04-07 18:17 - 00000000 ___RD () C:\Users\Uzivatel\Desktop\Hry
2014-04-08 14:21 - 2013-11-03 18:21 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-04-08 14:11 - 2014-03-30 12:52 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-04-08 12:58 - 2013-09-03 14:18 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-08 12:57 - 2013-07-13 09:12 - 00000000 ____D () C:\windows\Minidump
2014-04-08 12:52 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-04-08 06:57 - 2014-04-08 06:57 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Updater
2014-04-07 19:14 - 2013-09-10 16:05 - 00124416 ___SH () C:\Users\Uzivatel\Desktop\Thumbs.db
2014-04-07 19:04 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\rescache
2014-04-07 18:32 - 2014-04-07 18:32 - 00001041 _____ () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hádanka – zástupce.lnk
2014-04-07 16:09 - 2013-09-07 12:17 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\vlc
2014-04-03 17:06 - 2013-10-10 16:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons
2014-04-01 16:57 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-03-31 08:38 - 2013-11-19 14:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 08:38 - 2013-09-21 14:01 - 00022880 _____ () C:\windows\PFRO.log
2014-03-30 13:17 - 2014-03-30 13:16 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-03-30 13:14 - 2014-03-30 12:52 - 00001104 _____ () C:\Users\Uzivatel\Desktop\StarCraft II.lnk
2014-03-30 12:23 - 2014-03-30 11:50 - 00000000 ____D () C:\Program Files (x86)\Warcraft II
2014-03-29 22:16 - 2013-07-16 12:11 - 00000760 _____ () C:\Users\Uzivatel\tajné.txt
2014-03-29 22:08 - 2013-07-14 12:11 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-03-29 12:03 - 2014-03-29 12:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:38 - 2014-03-29 11:38 - 00000000 ____D () C:\Users\Uzivatel\Downloads\StarCraft.II.Wings.of.Liberty - RELOADED
2014-03-27 18:35 - 2013-10-04 20:07 - 00000132 _____ () C:\Users\Uzivatel\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\Documents\Might & Magic Heroes VI
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Might & Magic Heroes VI
2014-03-27 15:19 - 2014-03-27 14:41 - 00000000 ____D () C:\Program Files (x86)\Might & Magic Heroes VI
2014-03-26 22:15 - 2013-03-14 09:49 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-26 21:43 - 2014-03-26 21:41 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Ubisoft Game Launcher
2014-03-26 19:48 - 2014-03-26 19:39 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-03-23 19:26 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\Documents\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\cache
2014-03-23 19:04 - 2013-09-19 18:59 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-03-23 19:01 - 2014-03-23 19:01 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Cheat Tables
2014-03-23 19:01 - 2014-03-16 10:32 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V - Tribes of the East
2014-03-23 19:01 - 2013-09-18 14:20 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\OpenCandy
2014-03-21 22:35 - 2014-03-21 22:35 - 04930704 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-17 20:47 - 2014-03-15 22:14 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V
2014-03-16 10:46 - 2013-10-28 18:07 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Games
Some content of TEMP:
====================
C:\Users\Uzivatel\AppData\Local\Temp\7za.exe
C:\Users\Uzivatel\AppData\Local\Temp\APNSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\AutoRun.exe
C:\Users\Uzivatel\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Uzivatel\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\Uzivatel\AppData\Local\Temp\bitool.dll
C:\Users\Uzivatel\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\comver.dll
C:\Users\Uzivatel\AppData\Local\Temp\Delta.exe
C:\Users\Uzivatel\AppData\Local\Temp\DeltaTB.exe
C:\Users\Uzivatel\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Uzivatel\AppData\Local\Temp\DTLite4481-0347.exe
C:\Users\Uzivatel\AppData\Local\Temp\eauninstall.exe
C:\Users\Uzivatel\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Uzivatel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Uzivatel\AppData\Local\Temp\ICReinstall_Overlord-2-Trailer.mov - CHIP Downloader.exe
C:\Users\Uzivatel\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Uzivatel\AppData\Local\Temp\ose00000.exe
C:\Users\Uzivatel\AppData\Local\Temp\propsys.dll
C:\Users\Uzivatel\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\sSetup-se.exe
C:\Users\Uzivatel\AppData\Local\Temp\The Battle for Middle-earth II_uninst.exe
C:\Users\Uzivatel\AppData\Local\Temp\TsuB86FBAFE.dll
C:\Users\Uzivatel\AppData\Local\Temp\ubiC097.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\ubiC9EE.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\ubiD3C7.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-1208.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-2436.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-2684.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-3608.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-3808.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-456.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-4916.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-4936.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-5012.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-5080.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-724.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-872.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-996.exe
C:\Users\Uzivatel\AppData\Local\Temp\WSSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\_is3300.exe
C:\Users\Uzivatel\AppData\Local\Temp\_is384A.exe
C:\Users\Uzivatel\AppData\Local\Temp\_isB439.exe
C:\Users\Uzivatel\AppData\Local\Temp\_isBED1.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-07 16:54
==================== End Of Log ============================
Mám malý problém. Ve složce uživatel se mi furt objevují dva soubory : regbcm, rgmnr. Když je odstraním při dalším spuštění notebooku tam zase jsou. Když spustím antivirus Windows Defender tak mě nic nenajde. Možná o nic nejde ale mám strach, že by to mohlo vyvrcholit v něco horšího. Prosím poraďte mi co mám dělat. Děkuji.
Zde je log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by Uzivatel (administrator) on LENOVO on 15-04-2014 13:50:20
Running from C:\Users\Uzivatel\Downloads
Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\windows\system32\BtwRSupportService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems Inc.) C:\windows\system32\CxAudMsg64.exe
(Microsoft Corporation) C:\windows\system32\dashost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(SkypEmoticons) C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons\SE.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(BitTorrent Inc.) C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
() C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
() C:\windows\inf\msciuejuw\msciuejuw.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
() C:\windows\inf\msmigqmk\msmigqmk.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
(Microsoft Corporation) C:\windows\syswow64\wwahost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2872720 2012-10-03] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-03-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-03-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [172144 2012-12-14] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [399984 2012-12-14] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [441968 2012-12-14] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [139792 2012-11-08] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-11-08] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [msksceqSrv] => C:\windows\inf\msksceq.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1801168 2014-04-05] (APN)
HKLM-x32\...\Run: [mstrjjSrv] => C:\windows\inf\mstrjj.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MSStp] => C:\windows\SysWOW64\msstp.vbe [1419 2014-01-19] ()
HKLM-x32\...\Run: [mncqrorcSrv] => C:\windows\inf\mncqrorc.vbe [1342 2014-01-19] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Google Update] => C:\Users\Uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-09] (Google Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [se] => C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons\SE.exe [5679008 2014-04-03] (SkypEmoticons)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [uTorrent] => C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-02-11] (BitTorrent Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Microsoft Application Manager] => C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe [193536 2014-03-26] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\MountPoints2: {65c2ff22-8c7a-11e2-be6b-806e6f6e6963} - "E:\Autorun.exe"
AppInit_DLLs: C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL => C:\Program Files (x86)\GS-Enabler\Browsafe_x64.dll [4581376 2013-12-27] ()
AppInit_DLLs-x32: c:\progra~2\gs-ena~1\browsafe.dll => C:\Program Files (x86)\GS-Enabler\Browsafe.dll [4370944 2013-12-27] ()
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registrationa1\RegistrationReminder.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registration\RegistrationReminder.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?o=APN10645A& ... 33-115&t=4
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
URLSearchHook: HKLM-x32 - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.)
URLSearchHook: HKCU - uTorrentControl_v6 Toolbar - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\Program Files (x86)\uTorrentControl_v6\prxtbuTor.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1377511855
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKLM-x32 - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL = http://www.bing.com/search?q={searchTer ... &pc=MALNJS
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-search.com/?q={search ... 3&tsp=4986
SearchScopes: HKCU - {164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKCU - {1BED6179-5314-4660-9C0A-CFFE4683E27E} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {23F84887-CA4F-4FD2-882A-EAE131127D23} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {32C87758-FF98-43A5-9F32-6C22364558E3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source= ... 1377513738
SearchScopes: HKCU - {475D1C03-1095-42B4-9EC4-06AC02B8127A} URL = http://search.conduit.com/ResultsExt.as ... 61163&UM=1
SearchScopes: HKCU - {5DFD4BF8-81DF-4AF6-871A-5F237F5CD584} URL = http://search.softonic.com/INF00176/tb_ ... d6e2&r=203
SearchScopes: HKCU - {5E678327-E17A-4DE1-84C2-BED62DCFDBF4} URL =
SearchScopes: HKCU - {6A0758B4-A0F2-49B7-965A-05FF41A44F3C} URL = http://search.aol.com/aol/search?s_it=t ... earchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {B57B17D2-6231-42BB-99B8-FEDD49A69D59} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKCU - {C08DC435-369D-48F5-BA6C-B88F83EE3846} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKCU - {FBD1D3B1-12D6-4CE7-8985-752FE8303783} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
BHO: TubeItAdBlockAop - {375E1565-9EF3-250C-B3BC-5D802D2DDCFB} - C:\ProgramData\TubeItAdBlockAop\Ic9Wjo.x64.dll ()
BHO: RandoomPrice - {49C3E4B7-B33C-29D1-8441-9D7291DCE897} - C:\ProgramData\RandoomPrice\E3SwWBi.x64.dll ()
BHO: CoupEextensuIon - {57DA1AB4-B7A1-B09C-41B7-D44D368537D6} - C:\ProgramData\CoupEextensuIon\kTk__m4.x64.dll ()
BHO: SaveeRExtoeNsion - {7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} - C:\ProgramData\SaveeRExtoeNsion\s.x64.dll ()
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: TubeItAdBlockAop - {375E1565-9EF3-250C-B3BC-5D802D2DDCFB} - C:\ProgramData\TubeItAdBlockAop\Ic9Wjo.dll ()
BHO-x32: RandoomPrice - {49C3E4B7-B33C-29D1-8441-9D7291DCE897} - C:\ProgramData\RandoomPrice\E3SwWBi.dll ()
BHO-x32: CoupEextensuIon - {57DA1AB4-B7A1-B09C-41B7-D44D368537D6} - C:\ProgramData\CoupEextensuIon\kTk__m4.dll ()
BHO-x32: SaveeRExtoeNsion - {7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} - C:\ProgramData\SaveeRExtoeNsion\s.dll ()
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {96F454EA-9D38-474F-B504-56193E00C1A5} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: google
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a10733-115&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=7491911322904840&o=APN10645&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: RandoomPrice - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\ni3w60@oaqh-zlzd.edu [2014-03-08]
FF Extension: TubeItAdBlockAop - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\skf1_0tg@iy-kajfqo.org [2014-02-05]
FF Extension: SaveeRExtoeNsion - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\uuue.oy@zkqtapxoft.com [2014-01-01]
FF Extension: CoupEextensuIon - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\yee7qo@qkiuoy.co.uk [2014-01-01]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-29]
FF HKLM-x32\...\Firefox\Extensions: [7go@7go.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com
FF Extension: 7Go Games - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com [2013-08-26]
FF HKLM-x32\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-08-26]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [7go@7go.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com
FF Extension: 7Go Games - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com [2013-08-26]
FF HKCU\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-08-26]
Chrome:
=======
CHR HomePage: https://www.google.com/?hl=cs
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Intel\xC2\xAE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\xC2\xAE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Unity Player) - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Google Update) - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Extension: (Google Drive) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-26]
CHR Extension: (YouTube) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-26]
CHR Extension: (Google Search) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-26]
CHR Extension: (CoupEextensuIon) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf [2013-12-31]
CHR Extension: (RandoomPrice) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda [2014-03-07]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkobdpgofbmhpeaedbmgjcfcecmedgoa [2013-11-13]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpjompbfihdbjohiipgldnoocmlnfdae [2013-11-13]
CHR Extension: (Pen\xC4\x9B\xC5\xBEenka Google) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (No Name) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf [2013-12-27]
CHR Extension: (Gmail) - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-26]
CHR Extension: (SaveeRExtoeNsion) - C:\ProgramData\odlcbfcjpeocknpekoimjlgimdpolpdf [2013-12-31]
CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-07-27]
CHR HKLM-x32\...\Chrome\Extension: [aaaaabcbmongicmdegkmmfgdickgnnob] - C:\Users\Uzivatel\AppData\Local\ilividmoviestoolbardla\GC\toolbar.crx [2013-06-12]
CHR HKLM-x32\...\Chrome\Extension: [aaaajpkhjdkhhnkmgfjodbkfpbmibkkk] - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7\CRX\ToolbarCR.crx [2014-04-05]
CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-07-27]
CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.19.3\Softonic.crx [2013-05-01]
CHR HKLM-x32\...\Chrome\Extension: [gjajpkikblccgefaibcafkfbanllpefi] - C:\Users\Uzivatel\AppData\Roaming\7go\7go.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-07-30]
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Uzivatel\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-07-30]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-04-05] (APN LLC.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2227992 2012-10-02] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [959256 2012-11-16] (Broadcom Corporation.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-04-12] (IvoSoft)
R2 e81a9dc1; C:\Program Files (x86)\GS-Enabler\BrowsafeSvc.dll [180048 2013-12-27] ()
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [83968 2012-09-05] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2013-11-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-01-07] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [169240 2012-10-02] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-11-10] (Disc Soft Ltd)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-01-07] ()
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8222736 2012-06-15] (Realtek Semiconductor Corp.)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-15 13:50 - 2014-04-15 13:51 - 00030740 _____ () C:\Users\Uzivatel\Downloads\FRST.txt
2014-04-15 13:50 - 2014-04-15 13:50 - 00000000 ____D () C:\FRST
2014-04-15 13:47 - 2014-04-15 13:47 - 02054144 _____ (Farbar) C:\Users\Uzivatel\Downloads\FRST64.exe
2014-04-13 19:36 - 2014-04-13 19:35 - 00011331 _____ () C:\Users\Uzivatel\Downloads\DayZ-1.7.1.torrent
2014-04-13 16:49 - 2014-04-15 13:11 - 00012991 _____ () C:\Users\Uzivatel\rgmnr
2014-04-13 16:48 - 2014-04-13 16:48 - 00000000 _____ () C:\Users\Uzivatel\regbcm
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\PAYDAY 2
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\EMU
2014-04-13 12:46 - 2014-04-13 12:46 - 00001159 _____ () C:\Users\Public\Desktop\PAYDAY 2.lnk
2014-04-13 12:15 - 2014-04-13 12:46 - 00000000 ____D () C:\Program Files (x86)\PAYDAY 2
2014-04-13 08:21 - 2014-04-13 12:13 - 3942678528 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD2.iso
2014-04-12 22:01 - 2014-04-13 05:56 - 4246634496 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD1.iso
2014-04-08 06:57 - 2014-04-08 06:57 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Updater
2014-04-07 18:32 - 2014-04-07 18:32 - 00001041 _____ () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hádanka – zástupce.lnk
2014-04-07 18:17 - 2014-04-08 16:16 - 00000000 ___RD () C:\Users\Uzivatel\Desktop\Hry
2014-03-30 13:16 - 2014-03-30 13:17 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-03-30 12:52 - 2014-04-08 17:51 - 00000000 ____D () C:\Users\Uzivatel\Documents\StarCraft II
2014-03-30 12:52 - 2014-04-08 14:11 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-03-30 12:52 - 2014-03-30 13:14 - 00001104 _____ () C:\Users\Uzivatel\Desktop\StarCraft II.lnk
2014-03-30 11:50 - 2014-03-30 12:23 - 00000000 ____D () C:\Program Files (x86)\Warcraft II
2014-03-29 12:00 - 2014-03-29 12:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:38 - 2014-03-29 11:38 - 00000000 ____D () C:\Users\Uzivatel\Downloads\StarCraft.II.Wings.of.Liberty - RELOADED
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\Documents\Might & Magic Heroes VI
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Might & Magic Heroes VI
2014-03-27 14:41 - 2014-03-27 15:19 - 00000000 ____D () C:\Program Files (x86)\Might & Magic Heroes VI
2014-03-26 21:41 - 2014-03-26 21:43 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Ubisoft Game Launcher
2014-03-26 19:39 - 2014-03-26 19:48 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-03-23 19:11 - 2014-03-23 19:26 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\Documents\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\cache
2014-03-23 19:01 - 2014-03-23 19:01 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Cheat Tables
2014-03-21 22:35 - 2014-03-21 22:35 - 04930704 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 10:32 - 2014-03-23 19:01 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V - Tribes of the East
==================== One Month Modified Files and Folders =======
2014-04-15 13:51 - 2014-04-15 13:50 - 00030740 _____ () C:\Users\Uzivatel\Downloads\FRST.txt
2014-04-15 13:50 - 2014-04-15 13:50 - 00000000 ____D () C:\FRST
2014-04-15 13:50 - 2013-08-27 15:22 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\uTorrent
2014-04-15 13:47 - 2014-04-15 13:47 - 02054144 _____ (Farbar) C:\Users\Uzivatel\Downloads\FRST64.exe
2014-04-15 13:31 - 2013-09-21 16:59 - 01966644 _____ () C:\windows\WindowsUpdate.log
2014-04-15 13:19 - 2013-08-26 15:03 - 00000970 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-15 13:15 - 2013-07-12 09:09 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Seznam.cz
2014-04-15 13:14 - 2013-06-27 14:57 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-141415711-4277777738-1014465746-1002
2014-04-15 13:12 - 2013-03-14 10:37 - 00727488 _____ () C:\windows\system32\perfh005.dat
2014-04-15 13:12 - 2013-03-14 10:37 - 00148006 _____ () C:\windows\system32\perfc005.dat
2014-04-15 13:12 - 2012-07-26 09:28 - 01714430 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-15 13:11 - 2014-04-13 16:49 - 00012991 _____ () C:\Users\Uzivatel\rgmnr
2014-04-15 13:10 - 2013-06-27 14:51 - 00000000 ___RD () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-15 13:10 - 2013-06-27 14:49 - 00000000 ____D () C:\Users\Uzivatel
2014-04-15 13:09 - 2013-08-26 15:03 - 00000966 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-15 13:09 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-04-14 13:54 - 2013-07-09 17:15 - 00000988 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141415711-4277777738-1014465746-1002UA.job
2014-04-14 07:26 - 2013-08-29 07:54 - 00149504 ___SH () C:\Users\Uzivatel\Thumbs.db
2014-04-13 21:30 - 2013-07-09 17:15 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141415711-4277777738-1014465746-1002Core.job
2014-04-13 19:48 - 2013-07-18 13:23 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\DAEMON Tools Lite
2014-04-13 19:35 - 2014-04-13 19:36 - 00011331 _____ () C:\Users\Uzivatel\Downloads\DayZ-1.7.1.torrent
2014-04-13 16:48 - 2014-04-13 16:48 - 00000000 _____ () C:\Users\Uzivatel\regbcm
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\PAYDAY 2
2014-04-13 13:24 - 2014-04-13 13:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\EMU
2014-04-13 13:03 - 2013-09-21 15:19 - 00273436 _____ () C:\windows\DirectX.log
2014-04-13 12:46 - 2014-04-13 12:46 - 00001159 _____ () C:\Users\Public\Desktop\PAYDAY 2.lnk
2014-04-13 12:46 - 2014-04-13 12:15 - 00000000 ____D () C:\Program Files (x86)\PAYDAY 2
2014-04-13 12:13 - 2014-04-13 08:21 - 3942678528 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD2.iso
2014-04-13 05:56 - 2014-04-12 22:01 - 4246634496 _____ () C:\Users\Uzivatel\Downloads\PayDay-2---DVD1.iso
2014-04-11 18:28 - 2013-08-14 20:39 - 00000000 ____D () C:\windows\system32\MRT
2014-04-11 18:02 - 2013-06-27 15:43 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-10 20:17 - 2013-10-10 15:48 - 00015643 _____ () C:\windows\setupact.log
2014-04-10 20:02 - 2013-08-26 08:29 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\File Scout
2014-04-09 21:17 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-09 18:27 - 2013-07-09 12:53 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Skype
2014-04-09 18:26 - 2013-07-09 10:31 - 00000000 ____D () C:\Users\Uzivatel\Documents\Youcam
2014-04-08 21:26 - 2013-11-03 18:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Battle.net
2014-04-08 17:51 - 2014-03-30 12:52 - 00000000 ____D () C:\Users\Uzivatel\Documents\StarCraft II
2014-04-08 16:16 - 2014-04-07 18:17 - 00000000 ___RD () C:\Users\Uzivatel\Desktop\Hry
2014-04-08 14:21 - 2013-11-03 18:21 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-04-08 14:11 - 2014-03-30 12:52 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-04-08 12:58 - 2013-09-03 14:18 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-08 12:57 - 2013-07-13 09:12 - 00000000 ____D () C:\windows\Minidump
2014-04-08 12:52 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-04-08 06:57 - 2014-04-08 06:57 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Updater
2014-04-07 19:14 - 2013-09-10 16:05 - 00124416 ___SH () C:\Users\Uzivatel\Desktop\Thumbs.db
2014-04-07 19:04 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\rescache
2014-04-07 18:32 - 2014-04-07 18:32 - 00001041 _____ () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hádanka – zástupce.lnk
2014-04-07 16:09 - 2013-09-07 12:17 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\vlc
2014-04-03 17:06 - 2013-10-10 16:24 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons
2014-04-01 16:57 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-03-31 08:38 - 2013-11-19 14:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 08:38 - 2013-09-21 14:01 - 00022880 _____ () C:\windows\PFRO.log
2014-03-30 13:17 - 2014-03-30 13:16 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
2014-03-30 13:14 - 2014-03-30 12:52 - 00001104 _____ () C:\Users\Uzivatel\Desktop\StarCraft II.lnk
2014-03-30 12:23 - 2014-03-30 11:50 - 00000000 ____D () C:\Program Files (x86)\Warcraft II
2014-03-29 22:16 - 2013-07-16 12:11 - 00000760 _____ () C:\Users\Uzivatel\tajné.txt
2014-03-29 22:08 - 2013-07-14 12:11 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-03-29 12:03 - 2014-03-29 12:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-29 11:38 - 2014-03-29 11:38 - 00000000 ____D () C:\Users\Uzivatel\Downloads\StarCraft.II.Wings.of.Liberty - RELOADED
2014-03-27 18:35 - 2013-10-04 20:07 - 00000132 _____ () C:\Users\Uzivatel\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\Documents\Might & Magic Heroes VI
2014-03-27 15:21 - 2014-03-27 15:21 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\Might & Magic Heroes VI
2014-03-27 15:19 - 2014-03-27 14:41 - 00000000 ____D () C:\Program Files (x86)\Might & Magic Heroes VI
2014-03-26 22:15 - 2013-03-14 09:49 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-26 21:43 - 2014-03-26 21:41 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Ubisoft Game Launcher
2014-03-26 19:48 - 2014-03-26 19:39 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-03-23 19:26 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\Documents\Mobogenie
2014-03-23 19:11 - 2014-03-23 19:11 - 00000000 ____D () C:\Users\Uzivatel\AppData\Local\cache
2014-03-23 19:04 - 2013-09-19 18:59 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-03-23 19:01 - 2014-03-23 19:01 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Cheat Tables
2014-03-23 19:01 - 2014-03-16 10:32 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V - Tribes of the East
2014-03-23 19:01 - 2013-09-18 14:20 - 00000000 ____D () C:\Users\Uzivatel\AppData\Roaming\OpenCandy
2014-03-21 22:35 - 2014-03-21 22:35 - 04930704 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-17 20:47 - 2014-03-15 22:14 - 00000000 ____D () C:\Program Files (x86)\Heroes of Might and Magic V
2014-03-16 10:46 - 2013-10-28 18:07 - 00000000 ____D () C:\Users\Uzivatel\Documents\My Games
Some content of TEMP:
====================
C:\Users\Uzivatel\AppData\Local\Temp\7za.exe
C:\Users\Uzivatel\AppData\Local\Temp\APNSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\AutoRun.exe
C:\Users\Uzivatel\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Uzivatel\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\Uzivatel\AppData\Local\Temp\bitool.dll
C:\Users\Uzivatel\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\comver.dll
C:\Users\Uzivatel\AppData\Local\Temp\Delta.exe
C:\Users\Uzivatel\AppData\Local\Temp\DeltaTB.exe
C:\Users\Uzivatel\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Uzivatel\AppData\Local\Temp\DTLite4481-0347.exe
C:\Users\Uzivatel\AppData\Local\Temp\eauninstall.exe
C:\Users\Uzivatel\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Uzivatel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Uzivatel\AppData\Local\Temp\ICReinstall_Overlord-2-Trailer.mov - CHIP Downloader.exe
C:\Users\Uzivatel\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Uzivatel\AppData\Local\Temp\ose00000.exe
C:\Users\Uzivatel\AppData\Local\Temp\propsys.dll
C:\Users\Uzivatel\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\sSetup-se.exe
C:\Users\Uzivatel\AppData\Local\Temp\The Battle for Middle-earth II_uninst.exe
C:\Users\Uzivatel\AppData\Local\Temp\TsuB86FBAFE.dll
C:\Users\Uzivatel\AppData\Local\Temp\ubiC097.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\ubiC9EE.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\ubiD3C7.tmp.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-1208.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-2436.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-2684.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-3608.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-3808.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-456.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-4916.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-4936.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-5012.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-5080.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-724.exe
C:\Users\Uzivatel\AppData\Local\Temp\UNINSTALLER-872.exe
C:\Users\Uzivatel\AppData\Local\Temp\Uninstaller-996.exe
C:\Users\Uzivatel\AppData\Local\Temp\WSSetup.exe
C:\Users\Uzivatel\AppData\Local\Temp\_is3300.exe
C:\Users\Uzivatel\AppData\Local\Temp\_is384A.exe
C:\Users\Uzivatel\AppData\Local\Temp\_isB439.exe
C:\Users\Uzivatel\AppData\Local\Temp\_isBED1.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-07 16:54
==================== End Of Log ============================
Re: Neznámé soubory ve složce uživatele
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Neznámé soubory ve složce uživatele
Tady je ten log :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 8 x64
Ran by Uzivatel on Łt 15. 04. 2014 at 15:39:18,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] APNMCP
Successfully deleted: [Service] APNMCP
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortapp.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escorteng.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortlbr.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\apn dtx
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilividmoviestoolbardla
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\omigaplussvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.dskbnd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.dskbnd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.softonichlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.softonichlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonicapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonicapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\srv.softonicsrvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\srv.softonicsrvc.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbardlaie
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\softonic
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{c670dcae-e392-aa32-6f42-143c7fc4bdfd}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3289075
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{475D1C03-1095-42B4-9EC4-06AC02B8127A}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5DFD4BF8-81DF-4AF6-871A-5F237F5CD584}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A0758B4-A0F2-49B7-965A-05FF41A44F3C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C08DC435-369D-48F5-BA6C-B88F83EE3846}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\askpartnernetwork"
~~~ Files
Successfully disinfected: [Shortcut] C:\Users\Uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Successfully disinfected: [Shortcut] C:\Users\Uzivatel\AppData\Roaming\microsoft\windows\start menu\Programs\Internet Explorer.lnk
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\datamngr"
Successfully deleted: [Folder] "C:\ProgramData\esafe"
Successfully deleted: [Folder] "C:\ProgramData\ibupdaterservice"
Successfully deleted: [Folder] "C:\ProgramData\wincert"
Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\desk 365"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\file scout"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\similarsites"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\softonic"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\ilividmoviestoolbardla"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\searchresultstb"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\softonic"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\movies toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\similarsites"
Successfully deleted: [Folder] "C:\Program Files (x86)\softonic"
Successfully deleted: [Folder] "C:\Program Files (x86)\youtubeadblocker"
Successfully deleted: [Folder] "C:\ProgramData\AskPartnerNetwork"
Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork"
~~~ FireFox
Successfully deleted: [File] C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\searchplugins\ask.xml
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\7go@7go.com
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions\\7go@7go.com
Successfully deleted the following from C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\prefs.js
user_pref("extensions.Gv3Kva36S.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexO
user_pref("extensions.Z5MCVMmf.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf
user_pref("extensions.bCF6x18xi.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp000008
user_pref("extensions.k3u.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>
user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a10733-115&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=7491911322904840&o=APN10645&q="
Emptied folder: C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\minidumps [27 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 15. 04. 2014 at 15:50:06,12
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 8 x64
Ran by Uzivatel on Łt 15. 04. 2014 at 15:39:18,60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] APNMCP
Successfully deleted: [Service] APNMCP
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortapp.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escorteng.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortlbr.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\apn dtx
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilividmoviestoolbardla
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\omigaplussvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.dskbnd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.dskbnd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.softonichlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonic.softonichlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonicapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\softonicapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\srv.softonicsrvc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\srv.softonicsrvc.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbardlaie
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\softonic
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{c670dcae-e392-aa32-6f42-143c7fc4bdfd}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3289075
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{475D1C03-1095-42B4-9EC4-06AC02B8127A}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5DFD4BF8-81DF-4AF6-871A-5F237F5CD584}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6A0758B4-A0F2-49B7-965A-05FF41A44F3C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C08DC435-369D-48F5-BA6C-B88F83EE3846}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{49C3E4B7-B33C-29D1-8441-9D7291DCE897}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\askpartnernetwork"
~~~ Files
Successfully disinfected: [Shortcut] C:\Users\Uzivatel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Successfully disinfected: [Shortcut] C:\Users\Uzivatel\AppData\Roaming\microsoft\windows\start menu\Programs\Internet Explorer.lnk
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\datamngr"
Successfully deleted: [Folder] "C:\ProgramData\esafe"
Successfully deleted: [Folder] "C:\ProgramData\ibupdaterservice"
Successfully deleted: [Folder] "C:\ProgramData\wincert"
Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\desk 365"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\file scout"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\similarsites"
Successfully deleted: [Folder] "C:\Users\Uzivatel\AppData\Roaming\softonic"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\ilividmoviestoolbardla"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\searchresultstb"
Successfully deleted: [Folder] "C:\Users\Uzivatel\appdata\locallow\softonic"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\movies toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\similarsites"
Successfully deleted: [Folder] "C:\Program Files (x86)\softonic"
Successfully deleted: [Folder] "C:\Program Files (x86)\youtubeadblocker"
Successfully deleted: [Folder] "C:\ProgramData\AskPartnerNetwork"
Successfully deleted: [Folder] "C:\Program Files (x86)\askpartnernetwork"
~~~ FireFox
Successfully deleted: [File] C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\searchplugins\ask.xml
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\7go@7go.com
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions\\7go@7go.com
Successfully deleted the following from C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\prefs.js
user_pref("extensions.Gv3Kva36S.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexO
user_pref("extensions.Z5MCVMmf.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf
user_pref("extensions.bCF6x18xi.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp000008
user_pref("extensions.k3u.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>
user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=484&systemid=406&v=a10733-115&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=7491911322904840&o=APN10645&q="
Emptied folder: C:\Users\Uzivatel\AppData\Roaming\mozilla\firefox\profiles\a24l5ghm.default\minidumps [27 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 15. 04. 2014 at 15:50:06,12
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Neznámé soubory ve složce uživatele
Jeste prosim AdwCleaner
Re: Neznámé soubory ve složce uživatele
# AdwCleaner v3.023 - Report created 15/04/2014 at 18:16:49
# Updated 01/04/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Uzivatel - LENOVO
# Running from : C:\Users\Uzivatel\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\WinterSoft
Folder Deleted : C:\ProgramData\DDownLLOaDD keeper
Folder Deleted : C:\ProgramData\SearchNewTab
Folder Deleted : C:\ProgramData\suirrF uandd keep
Folder Deleted : C:\ProgramData\surefNkeepu
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
Folder Deleted : C:\Program Files (x86)\GS-Enabler
Folder Deleted : C:\Program Files (x86)\suirrF uandd keep
Folder Deleted : C:\Program Files (x86)\surefNkeepu
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v6
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
Folder Deleted : C:\Users\Uzivatel\AppData\Local\Conduit
Folder Deleted : C:\Users\Uzivatel\AppData\Local\cool_mirage
Folder Deleted : C:\Users\Uzivatel\AppData\Local\ilividmoviestoolbardla
Folder Deleted : C:\Users\Uzivatel\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Uzivatel\AppData\Local\torch
Folder Deleted : C:\Users\Uzivatel\AppData\LocalLow\uTorrentControl_v6
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\337
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\7go
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Omiga Plus
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\SpeedAnalysis2
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com
Folder Deleted : C:\Users\Uzivatel\Documents\Mobogenie
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\ni3w60@oaqh-zlzd.edu
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\skf1_0tg@iy-kajfqo.org
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\uuue.oy@zkqtapxoft.com
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\yee7qo@qkiuoy.co.uk
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\Uzivatel\AppData\Roaming\speedanalysis.ico
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml
File Deleted : C:\WINDOWS\System32\Tasks\Desk 365 RunAsStdUser
File Deleted : C:\WINDOWS\System32\Tasks\Omiga Plus RunAsStdUser
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [se]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DBB6CE-3148-4FEC-B481-103CB3290427}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8F80255A-3725-4FA3-9F3F-1F97B5969931}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F83C6660-8578-47FF-AD29-DAA3210FE041}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKCU\Software\AppDataLow\Software\ilividmoviestoolbardla
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v6
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Desksvc
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\omigaplusSvc
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\qvo6Software
Key Deleted : HKLM\Software\Softonic
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\uTorrentControl_v6
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SkypEmoticons_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v6 Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v28.0 (cs)
[ File : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js ]
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("extensions.Gv3Kva36S.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.i[...]
Line Deleted : user_pref("extensions.Z5MCVMmf.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.in[...]
Line Deleted : user_pref("extensions.bCF6x18xi.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"s[...]
Line Deleted : user_pref("extensions.k3u.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorob[...]
-\\ Google Chrome v
[ File : C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [14823 octets] - [15/04/2014 18:14:01]
AdwCleaner[S0].txt - [13483 octets] - [15/04/2014 18:16:49]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13544 octets] ##########
# Updated 01/04/2014 by Xplode
# Operating System : Windows 8.1 (64 bits)
# Username : Uzivatel - LENOVO
# Running from : C:\Users\Uzivatel\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\WinterSoft
Folder Deleted : C:\ProgramData\DDownLLOaDD keeper
Folder Deleted : C:\ProgramData\SearchNewTab
Folder Deleted : C:\ProgramData\suirrF uandd keep
Folder Deleted : C:\ProgramData\surefNkeepu
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons
Folder Deleted : C:\Program Files (x86)\GS-Enabler
Folder Deleted : C:\Program Files (x86)\suirrF uandd keep
Folder Deleted : C:\Program Files (x86)\surefNkeepu
Folder Deleted : C:\Program Files (x86)\uTorrentControl_v6
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
Folder Deleted : C:\Users\Uzivatel\AppData\Local\Conduit
Folder Deleted : C:\Users\Uzivatel\AppData\Local\cool_mirage
Folder Deleted : C:\Users\Uzivatel\AppData\Local\ilividmoviestoolbardla
Folder Deleted : C:\Users\Uzivatel\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Uzivatel\AppData\Local\torch
Folder Deleted : C:\Users\Uzivatel\AppData\LocalLow\uTorrentControl_v6
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\337
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\7go
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Omiga Plus
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\SkypEmoticons
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\SpeedAnalysis2
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\WinZipper
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com
Folder Deleted : C:\Users\Uzivatel\Documents\Mobogenie
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\ni3w60@oaqh-zlzd.edu
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\skf1_0tg@iy-kajfqo.org
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\uuue.oy@zkqtapxoft.com
Folder Deleted : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\Extensions\yee7qo@qkiuoy.co.uk
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\Users\Uzivatel\AppData\Roaming\speedanalysis.ico
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\Ask.xml
File Deleted : C:\WINDOWS\System32\Tasks\Desk 365 RunAsStdUser
File Deleted : C:\WINDOWS\System32\Tasks\Omiga Plus RunAsStdUser
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\elchiiiejkobdbblfejjkbphbddgmljf
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [se]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DBB6CE-3148-4FEC-B481-103CB3290427}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41564952-412D-5637-00A7-7A786E7484D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{96F454EA-9D38-474F-B504-56193E00C1A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CD90659F-D5B2-4104-9504-7CA36E6532DF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8F80255A-3725-4FA3-9F3F-1F97B5969931}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F83C6660-8578-47FF-AD29-DAA3210FE041}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKCU\Software\AppDataLow\Software\ilividmoviestoolbardla
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v6
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\AskPartnerNetwork
Key Deleted : HKLM\Software\Desksvc
Key Deleted : HKLM\Software\hdcode
Key Deleted : HKLM\Software\omigaplusSvc
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\qvo6Software
Key Deleted : HKLM\Software\Softonic
Key Deleted : HKLM\Software\Uniblue
Key Deleted : HKLM\Software\winzipersvc
Key Deleted : HKLM\Software\uTorrentControl_v6
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A35CA8FF-CB7D-8361-1CB9-83219CD11C78}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SkypEmoticons_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v6 Toolbar
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v28.0 (cs)
[ File : C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js ]
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("extensions.Gv3Kva36S.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.i[...]
Line Deleted : user_pref("extensions.Z5MCVMmf.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.in[...]
Line Deleted : user_pref("extensions.bCF6x18xi.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"s[...]
Line Deleted : user_pref("extensions.k3u.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorob[...]
-\\ Google Chrome v
[ File : C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [14823 octets] - [15/04/2014 18:14:01]
AdwCleaner[S0].txt - [13483 octets] - [15/04/2014 18:16:49]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13544 octets] ##########
Re: Neznámé soubory ve složce uživatele
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Neznámé soubory ve složce uživatele
Co když používám Windows 8
Re: Neznámé soubory ve složce uživatele
Spustte normalne dvouklikem 
Re: Neznámé soubory ve složce uživatele
Počítač se nerestartoval ale začalo to něco psát.
Re: Neznámé soubory ve složce uživatele
Tak jej nechte pracovat, on by si mel restart na konci vyzadat
Re: Neznámé soubory ve složce uživatele
Už v pohodě PC se restartovalo.
Tady je ten log :
Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Uzivatel on Łt 15. 04. 2014 at 18:34:04,09.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Uzivatel\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15. 4. 2014 18:39:48 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{73AD5D47-66E5-4127-80CA-C0EEDABAFBCC} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js:
user_pref("browser.startup.homepage", "google");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
user.js not found
---- Lines extensions.Gv3Kva36S removed from prefs.js ----
user_pref("extensions.Gv3Kva36S.epoch", "1397646657");
user_pref("extensions.Gv3Kva36S.url", "http://driverguidemy.ru/sync2/?q=hfZ9oe ... qda9rjkFrj
---- Lines extensions.VA2etW removed from prefs.js ----
user_pref("extensions.VA2etW.epoch", "1388419259");
user_pref("extensions.VA2etW.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.protoco
user_pref("extensions.VA2etW.url", "http://jpi-syncs.info/sync2/?q=hfZ9oeFP ... TUFqTaEqjY
---- Lines extensions.Z5MCVMmf removed from prefs.js ----
user_pref("extensions.Z5MCVMmf.epoch", "1397646657");
user_pref("extensions.Z5MCVMmf.url", "http://toolkitsetusa.info/sync2/?q=hfZ9 ... Eqdw8rjwFr
---- Lines extensions.bCF6x18xi removed from prefs.js ----
user_pref("extensions.bCF6x18xi.epoch", "1397646657");
user_pref("extensions.bCF6x18xi.url", "http://jpisyncer.info/sync2/?q=hfZ9ofhT ... kFrjwErHgM
---- Lines extensions.k3u removed from prefs.js ----
user_pref("extensions.k3u.epoch", "1397646657");
user_pref("extensions.k3u.url", "http://webterminall.in/sync2/?q=hfZ9ofD ... Frdr7tNhVC
---- FireFox user.js and prefs.js backups ----
prefs_201415.04._1910_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\odlcbfcjpeocknpekoimjlgimdpolpdf deleted
C:\Users\Uzivatel\AppData\LocalLow\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted
C:\Users\Uzivatel\AppData\LocalLow\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted
C:\Users\Uzivatel\AppData\LocalLow\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted
C:\Users\Uzivatel\AppData\LocalLow\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted
C:\Users\Uzivatel\AppData\LocalLow\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted
C:\Users\Uzivatel\AppData\LocalLow\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted
C:\PROGRA~3\776b531872b237e8 deleted
C:\PROGRA~3\HirezPipeError.txt deleted
C:\PROGRA~3\kbopdeecfojpibnmobikahpidencdlic deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\SummerSoft deleted
C:\Users\Uzivatel\AppData\Local\CRE deleted
C:\Users\Uzivatel\AppData\Local\cache deleted
C:\Users\Uzivatel\AppData\Roaming\ACRPR.exe deleted
C:\Users\Uzivatel\AppData\Roaming\AssassinsCreedRevelations.exe deleted
C:\Users\Uzivatel\AppData\Roaming\Uninstal.exe deleted
C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com deleted
C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com deleted
"C:\PROGRA~3\TubeItAdBlockAop\Ic9Wjo.dll" deleted
"C:\PROGRA~3\RandoomPrice\E3SwWBi.dll" deleted
"C:\PROGRA~3\CoupEextensuIon\kTk__m4.dll" deleted
"C:\PROGRA~3\SaveeRExtoeNsion\s.dll" deleted
"C:\PROGRA~3\RandoomPrice\E3SwWBi.dll" deleted
"C:\Users\Uzivatel\AppData\Roaming\Updater" deleted
"C:\PROGRA~3\TubeItAdBlockAop" deleted
"C:\PROGRA~3\RandoomPrice" not deleted
"C:\PROGRA~3\CoupEextensuIon" not deleted
"C:\PROGRA~3\SaveeRExtoeNsion" not deleted
"C:\PROGRA~3\RandoomPrice" not deleted
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
F6D12679B9112358AC705A1308156F59 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
C36444D7301A8C881FC7296B092609C7 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
EE8D96E7899D12FC3AA5DB2034C0853C - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll - Shockwave Flash
AF661355EBAB898EB92D5454AEF93CE0 - C:\windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43
369EC92E676537A3F86C5074BA30FC96 - C:\windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aaaajpkhjdkhhnkmgfjodbkfpbmibkkk - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7\CRX\ToolbarCR.crx[]
cflheckfmhopnialghigdlggahiomebp - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx[]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
cflheckfmhopnialghigdlggahiomebp - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx[]
surefNkeepu - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Uzivatel\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
CoupEextensuIon - Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf
RandoomPrice - Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda
surefNkeepu - Uzivatel\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
==== Chrome Fix ======================
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkobdpgofbmhpeaedbmgjcfcecmedgoa deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kkobdpgofbmhpeaedbmgjcfcecmedgoa_0.localstorage deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpjompbfihdbjohiipgldnoocmlnfdae deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mpjompbfihdbjohiipgldnoocmlnfdae_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_12454"
{1BED6179-5314-4660-9C0A-CFFE4683E27E} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_12454"
{23F84887-CA4F-4FD2-882A-EAE131127D23} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454"
{32C87758-FF98-43A5-9F32-6C22364558E3} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_12454"
{5E678327-E17A-4DE1-84C2-BED62DCFDBF4} Unknown Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{B57B17D2-6231-42BB-99B8-FEDD49A69D59} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"
{F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_12454"
{FBD1D3B1-12D6-4CE7-8985-752FE8303783} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
{FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
==== Reset Google Chrome ======================
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Internet Explorer\SearchScopes\{5E678327-E17A-4DE1-84C2-BED62DCFDBF4} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3732A804-BFB9-B88F-49AF-B050667D5C35} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A0CC002-77D5-692C-6E08-65F198B5EABB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\aaaajpkhjdkhhnkmgfjodbkfpbmibkkk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2349E803-9B10-7B83-C1CB-9C9F16739F60} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E8C2E2D-7F21-2CF5-0ADB-64935121ECF0} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6933C2BA-C67D-42C7-8C77-1FF4B364AF54} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{274E3C5C-178E-EAE2-A52F-2863C0EECD46} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbardlaGC deleted successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Uzivatel\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Uzivatel\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Uzivatel\AppData\Local\Mozilla\Firefox\Profiles\a24l5ghm.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=272 folders=101 61486567 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Users\Uzivatel\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Uzivatel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\PROGRA~3\RandoomPrice" not found
"C:\PROGRA~3\CoupEextensuIon" not found
"C:\PROGRA~3\SaveeRExtoeNsion" not found
"C:\PROGRA~3\RandoomPrice" not found
"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted
==== EOF on Łt 15. 04. 2014 at 19:23:45,09 ======================
Tady je ten log :
Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Uzivatel on Łt 15. 04. 2014 at 18:34:04,09.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Uzivatel\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15. 4. 2014 18:39:48 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{73AD5D47-66E5-4127-80CA-C0EEDABAFBCC} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js:
user_pref("browser.startup.homepage", "google");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
user.js not found
---- Lines extensions.Gv3Kva36S removed from prefs.js ----
user_pref("extensions.Gv3Kva36S.epoch", "1397646657");
user_pref("extensions.Gv3Kva36S.url", "http://driverguidemy.ru/sync2/?q=hfZ9oe ... qda9rjkFrj
---- Lines extensions.VA2etW removed from prefs.js ----
user_pref("extensions.VA2etW.epoch", "1388419259");
user_pref("extensions.VA2etW.scode", "(function(){if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};if(window.self.location.protoco
user_pref("extensions.VA2etW.url", "http://jpi-syncs.info/sync2/?q=hfZ9oeFP ... TUFqTaEqjY
---- Lines extensions.Z5MCVMmf removed from prefs.js ----
user_pref("extensions.Z5MCVMmf.epoch", "1397646657");
user_pref("extensions.Z5MCVMmf.url", "http://toolkitsetusa.info/sync2/?q=hfZ9 ... Eqdw8rjwFr
---- Lines extensions.bCF6x18xi removed from prefs.js ----
user_pref("extensions.bCF6x18xi.epoch", "1397646657");
user_pref("extensions.bCF6x18xi.url", "http://jpisyncer.info/sync2/?q=hfZ9ofhT ... kFrjwErHgM
---- Lines extensions.k3u removed from prefs.js ----
user_pref("extensions.k3u.epoch", "1397646657");
user_pref("extensions.k3u.url", "http://webterminall.in/sync2/?q=hfZ9ofD ... Frdr7tNhVC
---- FireFox user.js and prefs.js backups ----
prefs_201415.04._1910_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\odlcbfcjpeocknpekoimjlgimdpolpdf deleted
C:\Users\Uzivatel\AppData\LocalLow\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted
C:\Users\Uzivatel\AppData\LocalLow\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted
C:\Users\Uzivatel\AppData\LocalLow\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted
C:\Users\Uzivatel\AppData\LocalLow\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted
C:\Users\Uzivatel\AppData\LocalLow\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted
C:\Users\Uzivatel\AppData\LocalLow\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{8B26AA6C-7B45-C7AA-C4BA-B02CF913E0CB} deleted
C:\Users\Uzivatel\AppData\Local\Packages\windows_ie_ac_001\AC\{B08C5777-996A-3793-6FB9-C127AD7A353D} deleted
C:\PROGRA~3\776b531872b237e8 deleted
C:\PROGRA~3\HirezPipeError.txt deleted
C:\PROGRA~3\kbopdeecfojpibnmobikahpidencdlic deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\SummerSoft deleted
C:\Users\Uzivatel\AppData\Local\CRE deleted
C:\Users\Uzivatel\AppData\Local\cache deleted
C:\Users\Uzivatel\AppData\Roaming\ACRPR.exe deleted
C:\Users\Uzivatel\AppData\Roaming\AssassinsCreedRevelations.exe deleted
C:\Users\Uzivatel\AppData\Roaming\Uninstal.exe deleted
C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\7go@7go.com deleted
C:\Users\Uzivatel\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com deleted
"C:\PROGRA~3\TubeItAdBlockAop\Ic9Wjo.dll" deleted
"C:\PROGRA~3\RandoomPrice\E3SwWBi.dll" deleted
"C:\PROGRA~3\CoupEextensuIon\kTk__m4.dll" deleted
"C:\PROGRA~3\SaveeRExtoeNsion\s.dll" deleted
"C:\PROGRA~3\RandoomPrice\E3SwWBi.dll" deleted
"C:\Users\Uzivatel\AppData\Roaming\Updater" deleted
"C:\PROGRA~3\TubeItAdBlockAop" deleted
"C:\PROGRA~3\RandoomPrice" not deleted
"C:\PROGRA~3\CoupEextensuIon" not deleted
"C:\PROGRA~3\SaveeRExtoeNsion" not deleted
"C:\PROGRA~3\RandoomPrice" not deleted
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
F6D12679B9112358AC705A1308156F59 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
C36444D7301A8C881FC7296B092609C7 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
EE8D96E7899D12FC3AA5DB2034C0853C - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll - Shockwave Flash
AF661355EBAB898EB92D5454AEF93CE0 - C:\windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.400.43
369EC92E676537A3F86C5074BA30FC96 - C:\windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aaaajpkhjdkhhnkmgfjodbkfpbmibkkk - C:\ProgramData\AskPartnerNetwork\Toolbar\ORJ-V7\CRX\ToolbarCR.crx[]
cflheckfmhopnialghigdlggahiomebp - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx[]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
cflheckfmhopnialghigdlggahiomebp - C:\Users\Uzivatel\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx[]
surefNkeepu - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Administrator\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Guest\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
surefNkeepu - Uzivatel\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
CoupEextensuIon - Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf
RandoomPrice - Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda
surefNkeepu - Uzivatel\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf
==== Chrome Fix ======================
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ofhajajhggapkiebgknmnaafonnbccmf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fediekpkjghlbmjolecdbcjfnohidalf deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeicgbkochgbhkljpjocdmkggklbnda deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkobdpgofbmhpeaedbmgjcfcecmedgoa deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kkobdpgofbmhpeaedbmgjcfcecmedgoa_0.localstorage deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpjompbfihdbjohiipgldnoocmlnfdae deleted successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mpjompbfihdbjohiipgldnoocmlnfdae_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_12454"
{1BED6179-5314-4660-9C0A-CFFE4683E27E} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_12454"
{23F84887-CA4F-4FD2-882A-EAE131127D23} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454"
{32C87758-FF98-43A5-9F32-6C22364558E3} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_12454"
{5E678327-E17A-4DE1-84C2-BED62DCFDBF4} Unknown Url="Not_Found"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{B57B17D2-6231-42BB-99B8-FEDD49A69D59} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"
{F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_12454"
{FBD1D3B1-12D6-4CE7-8985-752FE8303783} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
{FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
==== Reset Google Chrome ======================
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_USERS\S-1-5-21-141415711-4277777738-1014465746-1002\Software\Microsoft\Internet Explorer\SearchScopes\{5E678327-E17A-4DE1-84C2-BED62DCFDBF4} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{375E1565-9EF3-250C-B3BC-5D802D2DDCFB} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49C3E4B7-B33C-29D1-8441-9D7291DCE897} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57DA1AB4-B7A1-B09C-41B7-D44D368537D6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DFEED0F-4CF8-ACB0-C251-6A5420F3F30D} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3732A804-BFB9-B88F-49AF-B050667D5C35} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A0CC002-77D5-692C-6E08-65F198B5EABB} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\aaaajpkhjdkhhnkmgfjodbkfpbmibkkk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2349E803-9B10-7B83-C1CB-9C9F16739F60} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{8E8C2E2D-7F21-2CF5-0ADB-64935121ECF0} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6933C2BA-C67D-42C7-8C77-1FF4B364AF54} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{274E3C5C-178E-EAE2-A52F-2863C0EECD46} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Your Software Deals_is1 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbardlaGC deleted successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Uzivatel\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Uzivatel\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Uzivatel\AppData\Local\Mozilla\Firefox\Profiles\a24l5ghm.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Uzivatel\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=272 folders=101 61486567 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Users\Uzivatel\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\Uzivatel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\PROGRA~3\RandoomPrice" not found
"C:\PROGRA~3\CoupEextensuIon" not found
"C:\PROGRA~3\SaveeRExtoeNsion" not found
"C:\PROGRA~3\RandoomPrice" not found
"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted
==== EOF on Łt 15. 04. 2014 at 19:23:45,09 ======================
Re: Neznámé soubory ve složce uživatele
Re: Neznámé soubory ve složce uživatele
Nevejde se to tam celé tak to musim rozdělit na části
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by Uzivatel (administrator) on LENOVO on 15-04-2014 19:36:51
Running from C:\Users\Uzivatel\Downloads
Windows 8.1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems Inc.) C:\windows\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(BitTorrent Inc.) C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
() C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\WINDOWS\inf\msciuejuw\msciuejuw.exe
() C:\WINDOWS\inf\msmigqmk\msmigqmk.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014
Ran by Uzivatel (administrator) on LENOVO on 15-04-2014 19:36:51
Running from C:\Users\Uzivatel\Downloads
Windows 8.1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Conexant Systems Inc.) C:\windows\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(BitTorrent Inc.) C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
() C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\WINDOWS\inf\msciuejuw\msciuejuw.exe
() C:\WINDOWS\inf\msmigqmk\msmigqmk.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\IEXPLORE.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
Re: Neznámé soubory ve složce uživatele
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2872720 2012-10-03] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [171992 2014-01-29] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\WINDOWS\system32\hkcmd.exe [399832 2014-01-29] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\WINDOWS\system32\igfxpers.exe [442328 2014-01-29] (Intel Corporation)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-03-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-03-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [139792 2012-11-08] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-11-08] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [msksceqSrv] => C:\windows\inf\msksceq.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [mstrjjSrv] => C:\windows\inf\mstrjj.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MSStp] => C:\windows\SysWOW64\msstp.vbe [1419 2014-01-19] ()
HKLM-x32\...\Run: [mncqrorcSrv] => C:\windows\inf\mncqrorc.vbe [1342 2014-01-19] ()
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Google Update] => C:\Users\Uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-09] (Google Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [uTorrent] => C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-02-11] (BitTorrent Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Microsoft Application Manager] => C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe [193536 2014-03-26] ()
AppInit_DLLs: C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL => C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL File Not Found
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [156256 2013-12-26] (NVIDIA Corporation)
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registrationa1\RegistrationReminder.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registration\RegistrationReminder.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKCU - {1BED6179-5314-4660-9C0A-CFFE4683E27E} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {23F84887-CA4F-4FD2-882A-EAE131127D23} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {32C87758-FF98-43A5-9F32-6C22364558E3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {B57B17D2-6231-42BB-99B8-FEDD49A69D59} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKCU - {F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKCU - {FBD1D3B1-12D6-4CE7-8985-752FE8303783} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2872720 2012-10-03] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IgfxTray] => C:\WINDOWS\system32\igfxtray.exe [171992 2014-01-29] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] => C:\WINDOWS\system32\hkcmd.exe [399832 2014-01-29] (Intel Corporation)
HKLM\...\Run: [Persistence] => C:\WINDOWS\system32\igfxpers.exe [442328 2014-01-29] (Intel Corporation)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-15] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2013-03-14] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2013-03-14] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-26] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [139792 2012-11-08] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-11-08] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [msksceqSrv] => C:\windows\inf\msksceq.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [mstrjjSrv] => C:\windows\inf\mstrjj.vbe [1558 2013-08-27] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [MSStp] => C:\windows\SysWOW64\msstp.vbe [1419 2014-01-19] ()
HKLM-x32\...\Run: [mncqrorcSrv] => C:\windows\inf\mncqrorc.vbe [1342 2014-01-19] ()
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Google Update] => C:\Users\Uzivatel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-09] (Google Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Uzivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [uTorrent] => C:\Users\Uzivatel\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-02-11] (BitTorrent Inc.)
HKU\S-1-5-21-141415711-4277777738-1014465746-1002\...\Run: [Microsoft Application Manager] => C:\Users\Uzivatel\AppData\Roaming\Microsoft\ApplicationManager\mst.exe [193536 2014-03-26] ()
AppInit_DLLs: C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL => C:\PROGRA~2\GS-ENA~1\BROWSA~1.DLL File Not Found
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [156256 2013-12-26] (NVIDIA Corporation)
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5 - Hammers of Fate.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registrationa1\RegistrationReminder.exe ()
Startup: C:\Users\Uzivatel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Heroes of Might & Magic 5.LNK
ShortcutTarget: Registration Heroes of Might & Magic 5.LNK -> C:\Program Files (x86)\Heroes of Might and Magic V\registration\RegistrationReminder.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {164A70F4-F6B3-4574-AB89-DC2CD55C2DD6} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKCU - {1BED6179-5314-4660-9C0A-CFFE4683E27E} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {23F84887-CA4F-4FD2-882A-EAE131127D23} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {32C87758-FF98-43A5-9F32-6C22364558E3} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {B57B17D2-6231-42BB-99B8-FEDD49A69D59} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKCU - {F59559C9-BB60-4BD9-99A4-F1A9A6B7760D} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKCU - {FBD1D3B1-12D6-4CE7-8985-752FE8303783} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {FFB84665-4DB7-4B6B-9A30-AB6C7369DC53} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Re: Neznámé soubory ve složce uživatele
FireFox:
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-29]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
========
FF ProfilePath: C:\Users\Uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\a24l5ghm.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Uzivatel\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Uzivatel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-29]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK



Přispějete na provoz fóra?