Maglajs v prohlížeči

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
fleker
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 18 Srp 2013 20:53

Maglajs v prohlížeči

#1 Příspěvek od fleker »

Ahoj,
potřebuju pomoc s odvirováním, každá druhá stránka mi hází chybu nebo se kousne a při každém restartu se mění se mění domovská stránka na QONE8, delta-search nebo yahoo. Jak mám postupovat?

Díky.

----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by fleker at 2014-05-26 11:01:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 44 GB (39%) free of 114 GB
Total RAM: 3327 MB (11% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:02:07, on 26.5.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17041)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\UnThreat AntiVirus\UnThreat.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Hotkeyp\HotkeyP.exe
C:\Users\fleker\AppData\Roaming\uTorrent\uTorrent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files\IObit\Smart Defrag 3\SmartDefrag.exe
C:\Program Files\SpyShelter Personal Free\SpyShelter.exe
C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Total Commander\TOTALCMD.EXE
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\COMODO\COMODO Internet Security\cis.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\GeniusPDF\GeniusPDF.EXE
C:\Program Files\Windows Doctor\WindowsDoctor.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
Q:\Downloads\RSIT.exe
C:\Program Files\trend micro\fleker.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.qone8.com/web/?type=ds&ts=14 ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.qone8.com/web/?type=ds&ts=14 ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.qone8.com/web/?type=ds&ts=14 ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.qone8.com/web/?type=ds&ts=14 ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL
O2 - BHO: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\28.0.1500.72\npchrome_frame.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe" -s
O4 - HKLM\..\Run: [UnThreat] "C:\Program Files\UnThreat AntiVirus\UnThreat.exe" -silent
O4 - HKLM\..\RunOnce: [SymInstallStub] C:\Windows\system32\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=5 /desktopshortcut=1 /startmenushortcut=1 /launchedby=3
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [EPSON S22 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGEE.EXE /FU "C:\Windows\TEMP\E_S589D.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [HotkeyP] C:\Program Files\Hotkeyp\HotkeyP.exe 0
O4 - HKCU\..\Run: [uTorrent] "C:\Users\fleker\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [SpyShelter] C:\Program Files\SpyShelter Personal Free\SpyShelter.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Google Chrome.lnk = C:\Program Files\Google\Chrome\Application\chrome.exe
O4 - Startup: Sticky Notes.lnk = ?
O4 - Startup: Total Commander.lnk = C:\Program Files\Total Commander\TOTALCMD.EXE
O4 - Global Startup: COMODO Firewall.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\28.0.1500.72\npchrome_frame.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: UnThreat Service Manager (UTSvcManager3) - Scandium Security Inc. - C:\Program Files\UnThreat AntiVirus\utsvc.exe

--
End of file - 10301 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Norton Product Installer.job - C:\Windows\system32\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=0 /desktopshortcut=1 /startmenushortcut=1 /launchedby=2
C:\Windows\tasks\Norton Product InstallerIdle.job - C:\Windows\system32\Adobe\Shockwave 12\SymInstallStub.exe /partnerid=adobe /productlist=nss /staging=false /delay=0 /desktopshortcut=1 /startmenushortcut=1 /launchedby=4

=========Mozilla firefox=========

ProfilePath - C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"quick_start@gmail.com"=C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\extensions\quick_start@gmail.com


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2027]
"Description"=RealMedia Plugin
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1040]
"Description"=6.0.12.1040
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.6]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\extensions\
extension@linkeyproject.com
fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
quick_start@gmail.com
savingsslider@mybrowserbar.com
WebSiteRecommendation@weliketheweb.com
{12DC3319-1C0A-106A-C0A9-19AC078CABBB}
{58d2a791-6199-482f-a9aa-9b725ec61362}
{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\searchplugins\
default-search.xml
yahoo_ff.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2014-05-04 752960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IObit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2014-02-20 669504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7}]
ChromeFrame BHO - C:\Program Files\Google\Chrome Frame\Application\28.0.1500.72\npchrome_frame.dll [2013-07-12 2379216]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-12-19 642808]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-04-02 3774312]
"IObit Malware Fighter"=C:\Program Files\IObit\IObit Malware Fighter\IMF.exe [2014-04-21 1596736]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [2014-05-18 6667992]
"UnThreat"=C:\Program Files\UnThreat AntiVirus\UnThreat.exe [2014-01-22 14911280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SymInstallStub"=C:\Windows\system32\Adobe\Shockwave 12\SymInstallStub.exe [2014-05-26 335776]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RESTART_STICKY_NOTES"=C:\Windows\System32\StikyNot.exe [2009-07-14 354304]
"EPSON S22 Series"=C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGEE.EXE [2009-09-14 200704]
"HotkeyP"=C:\Program Files\Hotkeyp\HotkeyP.exe [2013-05-30 60928]
"uTorrent"=C:\Users\fleker\AppData\Roaming\uTorrent\uTorrent.exe [2014-05-14 1272400]
"SpyShelter"=C:\Program Files\SpyShelter Personal Free\SpyShelter.exe [2014-02-13 5058912]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
COMODO Firewall.lnk - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe

C:\Users\fleker\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Google Chrome.lnk - C:\Program Files\Google\Chrome\Application\chrome.exe
Sticky Notes.lnk - C:\Windows\system32\StikyNot.exe
Total Commander.lnk - C:\Program Files\Total Commander\TOTALCMD.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"vidc.avrn"=C:\PROGRA~1\ACEMEG~1\SystemS\AVIDAV~1.DLL
"vidc.advj"=C:\PROGRA~1\ACEMEG~1\SystemS\AVIDAV~1.DLL
"vidc.mszh"=C:\PROGRA~1\ACEMEG~1\SystemS\avimszh.dll
"vidc.zlib"=C:\PROGRA~1\ACEMEG~1\SystemS\avizlib.dll
"vidc.cscd"=C:\PROGRA~1\ACEMEG~1\SystemS\camcodec.dll
"vidc.cvid"=C:\PROGRA~1\ACEMEG~1\SystemS\iccvid.dll
"msacm.trspch"=C:\PROGRA~1\ACEMEG~1\SystemS\tssoft32.acm
"vidc.em2v"=C:\PROGRA~1\ACEMEG~1\SystemS\etxcodec.dll
"vidc.mkvc"=C:\PROGRA~1\ACEMEG~1\SystemS\kmvidc32.dll
"vidc.hfyu"=C:\PROGRA~1\ACEMEG~1\SystemS\huffyuv.dll
"msacm.lameacm"=LameACM.acm
"msacm.lhacm"=C:\PROGRA~1\ACEMEG~1\SystemS\lhacm.acm
"msacm.l3acm"=C:\PROGRA~1\ACEMEG~1\SystemS\l3codecp.acm
"vidc.sjpg"=C:\PROGRA~1\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.dmb2"=C:\PROGRA~1\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.gepj"=C:\PROGRA~1\ACEMEG~1\SystemS\pmjpeg32.dll
"vidc.qpeg"=C:\PROGRA~1\ACEMEG~1\SystemS\Qpeg32.dll
"vidc.q1.0"=C:\PROGRA~1\ACEMEG~1\SystemS\Qpeg32.dll
"msacm.sl_anet"=C:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.tscc"=C:\PROGRA~1\ACEMEG~1\SystemS\tsccvid.dll
"vidc.vifp"=C:\PROGRA~1\ACEMEG~1\SystemS\vfcodec.dll
"vidc.wrpr"=C:\PROGRA~1\ACEMEG~1\SystemS\aviwrap.dll
"vidc.wnv1"=C:\PROGRA~1\ACEMEG~1\SystemS\wnvplay1.dll
"vidc.advs"=C:\PROGRA~1\ACEMEG~1\SystemS\Adaptec\Dvc.dll
"vidc.aflc"=C:\PROGRA~1\ACEMEG~1\SystemS\Autodesk\FLCCOD~1.DLL
"vidc.afli"=C:\PROGRA~1\ACEMEG~1\SystemS\Autodesk\FLCCOD~1.DLL
"vidc.aasc"=C:\PROGRA~1\ACEMEG~1\SystemS\Autodesk\Aasc32.dll
"vidc.aas4"=C:\PROGRA~1\ACEMEG~1\SystemS\Autodesk\Aasc32.dll
"vidc.asv1"=C:\PROGRA~1\ACEMEG~1\SystemS\ASUS\asusasv1.dll
"vidc.asv2"=C:\PROGRA~1\ACEMEG~1\SystemS\ASUS\asusasv2.dll
"vidc.asvx"=C:\PROGRA~1\ACEMEG~1\SystemS\ASUS\asusasv2.dll
"vidc.vcr1"=C:\PROGRA~1\ACEMEG~1\SystemS\ATI\ativcr1.dll
"vidc.vcr2"=C:\PROGRA~1\ACEMEG~1\SystemS\ATI\ativcr2.dll
"vidc.yv12"=C:\PROGRA~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.mwv1"=C:\PROGRA~1\ACEMEG~1\SystemS\Aware\icmw_32.dll
"vidc.bt20"=C:\PROGRA~1\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
"vidc.y41p"=C:\PROGRA~1\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
"msacm.pcdv"=C:\PROGRA~1\ACEMEG~1\SystemS\Canopus\pcdv.acm
"vidc.cdvc"=C:\PROGRA~1\ACEMEG~1\SystemS\Canopus\CSCCDVC.DLL
"vidc.ddvc"=C:\PROGRA~1\ACEMEG~1\SystemS\Canopus\CSCdvsd.DLL
"vidc.png1"=C:\PROGRA~1\ACEMEG~1\SystemS\Core\COREPN~1.DLL
"msacm.CoreFLAC_ACM"=C:\PROGRA~1\ACEMEG~1\SystemS\Core\COREFL~1.ACM
"vidc.davc"=C:\PROGRA~1\ACEMEG~1\SystemS\dicas\davcvfw.dll
"vidc.div3"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div5"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.mpg3"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32.dll
"vidc.div4"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.div6"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.ap41"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivXc32f.dll
"vidc.dvx4"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\divx4.dll
"vidc.divx"=C:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivX520.dll
"vidc.frwd"=C:\PROGRA~1\ACEMEG~1\SystemS\Forward\frwd.dll
"vidc.frwt"=C:\PROGRA~1\ACEMEG~1\SystemS\Forward\frwd.dll
"vidc.frwa"=C:\PROGRA~1\ACEMEG~1\SystemS\Forward\frwt.dll
"vidc.frwu"=C:\PROGRA~1\ACEMEG~1\SystemS\Forward\frwu.dll
"vidc.glzw"=C:\PROGRA~1\ACEMEG~1\SystemS\Gabest\GLZW.dll
"vidc.gpeg"=C:\PROGRA~1\ACEMEG~1\SystemS\Gabest\GPEG.dll
"vidc.i263"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\i263_32.drv
"vidc.iv30"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv31"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv32"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv33"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv34"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv35"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv36"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv37"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv38"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv39"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir32_32.dll
"vidc.iv40"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv41"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv42"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv43"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv44"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv45"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv46"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv47"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv48"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv49"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir41_32.dll
"vidc.iv50"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\ir50_32.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"vidc.ir21"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\IR21_R.DLL
"vidc.rt21"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\IR21_R.DLL
"msacm.imc"=C:\PROGRA~1\ACEMEG~1\SystemS\Intel\IMC32.ACM
"vidc.lead"=C:\PROGRA~1\ACEMEG~1\SystemS\LEAD\LCODCCMP.DLL
"vidc.dvsd"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dvc"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dvcs"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCDVD_32.DLL
"vidc.dcmj"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.avi1"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.avi2"=C:\PROGRA~1\ACEMEG~1\SystemS\MAINCO~1\MCMJPG32.DLL
"vidc.dv25"=C:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll
"vidc.dv50"=C:\PROGRA~1\ACEMEG~1\SystemS\Matrox\DigiVCap.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-05-26 11:00:24 ----SHD---- C:\Config.Msi
2014-05-26 10:49:43 ----D---- C:\Windows\system32\Adobe
2014-05-26 02:13:40 ----D---- C:\ProgramData\Licenses
2014-05-25 17:47:04 ----A---- C:\Windows\system32\drivers\glavcam.sys
2014-05-25 17:34:52 ----A---- C:\Windows\system32\wksprtPS.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\wksprt.exe
2014-05-25 17:34:52 ----A---- C:\Windows\system32\TSWbPrxy.exe
2014-05-25 17:34:52 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-25 17:34:52 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\tsgqec.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\rdpudd.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\rdpendp_winip.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\rdpcorets.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\mstscax.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\mstsc.exe
2014-05-25 17:34:52 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2014-05-25 17:34:52 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2014-05-25 17:34:52 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2014-05-25 17:34:52 ----A---- C:\Windows\system32\aaclient.dll
2014-05-25 16:57:23 ----D---- C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2014-05-25 14:04:30 ----D---- C:\ProgramData\UnThreat
2014-05-25 14:03:40 ----A---- C:\Windows\system32\drivers\sbapifs.sys
2014-05-25 14:03:06 ----D---- C:\Program Files\UnThreat AntiVirus
2014-05-25 14:01:57 ----A---- C:\Windows\system32\SpyShelterShellExt.dll
2014-05-25 14:01:57 ----A---- C:\Windows\system32\Osklauncher.exe
2014-05-25 14:01:57 ----A---- C:\Windows\system32\inject_logon_dll.dll
2014-05-25 14:01:56 ----D---- C:\Users\fleker\AppData\Roaming\SpyShelter
2014-05-25 14:01:56 ----D---- C:\Program Files\SpyShelter Personal Free
2014-05-25 13:31:10 ----D---- C:\Program Files\Enigma Software Group
2014-05-25 13:30:32 ----D---- C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2014-05-25 13:30:30 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2014-05-25 11:52:06 ----N---- C:\bootsqm.dat
2014-05-21 18:04:05 ----A---- C:\Windows\system32\ff_vfw.dll
2014-05-21 18:04:03 ----D---- C:\Program Files\ffdshow
2014-05-21 18:03:59 ----D---- C:\Users\fleker\AppData\Roaming\SupTab
2014-05-21 18:03:57 ----D---- C:\ProgramData\IePluginService
2014-05-21 18:03:56 ----D---- C:\Program Files\SupTab
2014-05-21 18:03:45 ----D---- C:\ProgramData\WPM
2014-05-21 18:02:33 ----D---- C:\Program Files\hdvidcodec.com
2014-05-18 20:33:51 ----A---- C:\Windows\system32\drivers\AtihdW73.sys
2014-05-18 20:33:51 ----A---- C:\Windows\system32\DelayAPO.dll
2014-05-18 19:45:00 ----A---- C:\Windows\system32\RtNicProp32.dll
2014-05-18 19:44:59 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2014-05-18 19:43:46 ----D---- C:\Program Files\AMD
2014-05-18 19:43:21 ----A---- C:\Windows\system32\OVDecode.dll
2014-05-18 19:43:21 ----A---- C:\Windows\system32\OpenVideo.dll
2014-05-18 19:43:21 ----A---- C:\Windows\system32\coinst_13.251.dll
2014-05-18 19:43:21 ----A---- C:\Windows\system32\clinfo.exe
2014-05-18 19:43:21 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2014-05-18 19:43:21 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2014-05-18 19:43:21 ----A---- C:\Windows\system32\ativce02.dat
2014-05-18 19:43:20 ----A---- C:\Windows\system32\atitmmxx.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2014-05-18 19:43:19 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atioglxx.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atimuixx.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atimpc32.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atiicdxx.dat
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atiglpxx.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atigktxx.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\amdpcom32.dll
2014-05-18 19:43:18 ----A---- C:\Windows\system32\aticalrt.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\OpenCL.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\aticaldd.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\aticalcl.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\atiapfxx.exe
2014-05-18 19:43:17 ----A---- C:\Windows\system32\amdocl_ld32.exe
2014-05-18 19:43:17 ----A---- C:\Windows\system32\amdocl_as32.exe
2014-05-18 19:43:16 ----A---- C:\Windows\system32\amdocl.dll
2014-05-18 19:41:30 ----A---- C:\Windows\system32\WavesGUILib.dll
2014-05-18 19:41:27 ----A---- C:\Windows\system32\sltech32.dll
2014-05-18 19:41:27 ----A---- C:\Windows\system32\slprp32.dll
2014-05-18 19:41:25 ----A---- C:\Windows\system32\slcnt32.dll
2014-05-18 19:41:25 ----A---- C:\Windows\system32\sl3apo32.dll
2014-05-18 19:41:25 ----A---- C:\Windows\system32\SFSS_APO.dll
2014-05-18 19:41:24 ----A---- C:\Windows\system32\drivers\rtvienna.dat
2014-05-18 19:41:23 ----A---- C:\Windows\system32\RtkPgExt.dll
2014-05-18 19:41:23 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2014-05-18 19:41:22 ----A---- C:\Windows\system32\RtkCoInstII.dll
2014-05-18 19:41:21 ----A---- C:\Windows\system32\RtkApoApi.dll
2014-05-18 19:41:21 ----A---- C:\Windows\system32\RtkAPO.dll
2014-05-18 19:41:19 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2014-05-18 19:41:18 ----A---- C:\Windows\system32\RCoRes.dat
2014-05-18 19:41:16 ----A---- C:\Windows\system32\NAHIMICAPOSettingsIPC.dll
2014-05-18 19:41:15 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2014-05-18 19:41:13 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2014-05-18 19:41:13 ----A---- C:\Windows\system32\MaxxVoiceAPO30.dll
2014-05-18 19:41:13 ----A---- C:\Windows\system32\MaxxVoiceAPO20.dll
2014-05-18 19:41:13 ----A---- C:\Windows\system32\MaxxSpeechAPO.dll
2014-05-18 19:41:12 ----A---- C:\Windows\system32\MaxxAudioVnN.dll
2014-05-18 19:41:11 ----A---- C:\Windows\system32\MaxxAudioVnA.dll
2014-05-18 19:41:10 ----A---- C:\Windows\system32\MaxxAudioRealtek2.dll
2014-05-18 19:41:09 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2014-05-18 19:41:08 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2014-05-18 19:41:08 ----A---- C:\Windows\system32\MaxxAudioAPOShell.dll
2014-05-18 19:41:08 ----A---- C:\Windows\system32\MaxxAudioAPO60.dll
2014-05-18 19:41:08 ----A---- C:\Windows\system32\MaxxAudioAPO50.dll
2014-05-18 19:41:07 ----A---- C:\Windows\system32\MaxxAudioAPO40.dll
2014-05-18 19:41:07 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2014-05-18 19:41:03 ----A---- C:\Windows\system32\FMAPO.dll
2014-05-18 19:41:03 ----A---- C:\Windows\system32\DTSU2PREC32.dll
2014-05-18 19:41:03 ----A---- C:\Windows\system32\DTSU2PLFX32.dll
2014-05-18 19:41:03 ----A---- C:\Windows\system32\DTSU2PGFX32.dll
2014-05-18 19:41:01 ----A---- C:\Windows\system32\DDPP32A.dll
2014-05-18 19:41:01 ----A---- C:\Windows\system32\DDPO32A.dll
2014-05-18 19:41:01 ----A---- C:\Windows\system32\DDPD32A.dll
2014-05-18 19:41:01 ----A---- C:\Windows\system32\DDPA32.dll
2014-05-18 19:41:01 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-05-18 19:40:59 ----A---- C:\Windows\system32\audioLibVc.dll
2014-05-18 19:40:58 ----A---- C:\Windows\system32\AERTACap.dll
2014-05-18 19:40:58 ----A---- C:\Windows\system32\AcpiServiceVnA.dll
2014-05-18 19:40:58 ----A---- C:\log.txt
2014-05-18 19:36:23 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2014-05-18 19:32:51 ----A---- C:\Windows\system32\IObitSmartDefragExtension.dll
2014-05-18 19:32:49 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2014-05-15 03:03:52 ----D---- C:\Program Files\Common Files\DESIGNER
2014-05-15 03:01:34 ----A---- C:\Windows\system32\mshtmled.dll
2014-05-15 03:01:31 ----A---- C:\Windows\system32\mshtml.dll
2014-05-14 20:36:52 ----A---- C:\Windows\system32\aepdu.dll
2014-05-14 20:36:51 ----A---- C:\Windows\system32\aeinv.dll
2014-05-14 20:27:09 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-05-14 20:27:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-05-14 20:27:08 ----A---- C:\Windows\system32\lsasrv.dll
2014-05-14 20:27:08 ----A---- C:\Windows\system32\kerberos.dll
2014-05-14 20:27:07 ----A---- C:\Windows\system32\winlogon.exe
2014-05-14 20:27:07 ----A---- C:\Windows\system32\wdigest.dll
2014-05-14 20:27:07 ----A---- C:\Windows\system32\TSpkg.dll
2014-05-14 20:27:07 ----A---- C:\Windows\system32\objsel.dll
2014-05-14 20:27:07 ----A---- C:\Windows\system32\msv1_0.dll
2014-05-14 20:27:07 ----A---- C:\Windows\system32\KernelBase.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\wincredprovider.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\sspisrv.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\sspicli.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\schannel.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\lsass.exe
2014-05-14 20:27:06 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-05-14 20:27:06 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-05-14 20:27:06 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\dimsroam.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\credssp.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\cngprovider.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\capiprovider.dll
2014-05-14 20:27:06 ----A---- C:\Windows\system32\adprovider.dll
2014-05-14 20:27:05 ----A---- C:\Windows\system32\secur32.dll
2014-05-14 20:23:03 ----A---- C:\Windows\system32\shell32.dll
2014-05-09 14:04:49 ----A---- C:\Windows\system32\qdvd.dll
2014-05-09 14:04:01 ----A---- C:\Windows\system32\RegistryDefragBootTime.exe
2014-05-07 03:00:31 ----SD---- C:\Windows\system32\CompatTel
2014-05-04 19:09:08 ----D---- C:\ProgramData\ProductData
2014-05-04 19:09:08 ----D---- C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
2014-05-04 19:09:06 ----D---- C:\ProgramData\IObit
2014-05-04 19:08:22 ----D---- C:\Program Files\IObit
2014-05-04 19:07:48 ----D---- C:\Users\fleker\AppData\Roaming\IObit
2014-05-04 18:16:26 ----D---- C:\Users\fleker\AppData\Roaming\eCyber
2014-05-04 18:15:54 ----D---- C:\Users\fleker\AppData\Roaming\iSafe
2014-05-03 10:31:18 ----D---- C:\ProgramData\systemk
2014-05-03 09:36:26 ----D---- C:\debug
2014-05-03 09:36:08 ----D---- C:\Program Files\Windows Doctor
2014-04-30 03:01:15 ----A---- C:\Windows\system32\vbscript.dll
2014-04-30 03:01:14 ----A---- C:\Windows\system32\ieui.dll
2014-04-30 03:01:05 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-04-30 03:01:04 ----A---- C:\Windows\system32\ieapfltr.dll
2014-04-30 03:01:02 ----A---- C:\Windows\system32\msrating.dll
2014-04-30 03:01:02 ----A---- C:\Windows\system32\msfeeds.dll
2014-04-30 03:01:02 ----A---- C:\Windows\system32\jsproxy.dll
2014-04-30 03:00:59 ----A---- C:\Windows\system32\dxtrans.dll
2014-04-30 03:00:59 ----A---- C:\Windows\system32\dxtmsft.dll
2014-04-30 03:00:58 ----A---- C:\Windows\system32\ie4uinit.exe
2014-04-30 03:00:57 ----A---- C:\Windows\system32\ieUnatt.exe
2014-04-30 03:00:57 ----A---- C:\Windows\system32\iesetup.dll
2014-04-30 03:00:57 ----A---- C:\Windows\system32\iernonce.dll
2014-04-30 03:00:56 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-30 03:00:55 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-30 03:00:55 ----A---- C:\Windows\system32\jscript9diag.dll
2014-04-30 03:00:55 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-04-30 03:00:55 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-04-30 03:00:48 ----A---- C:\Windows\system32\iertutil.dll
2014-04-30 03:00:47 ----A---- C:\Windows\system32\wininet.dll
2014-04-30 03:00:47 ----A---- C:\Windows\system32\urlmon.dll
2014-04-30 03:00:43 ----A---- C:\Windows\system32\ieframe.dll
2014-04-30 03:00:40 ----A---- C:\Windows\system32\jscript9.dll
2014-04-29 01:40:40 ----D---- C:\SuperWebcamRecorder
2014-04-29 01:40:31 ----D---- C:\Program Files\Zeallsoft
2014-04-29 01:31:09 ----D---- C:\ProgramData\NCH Software
2014-04-29 01:30:47 ----D---- C:\Program Files\CoffeeCup Software
2014-04-29 01:30:19 ----D---- C:\Users\fleker\AppData\Roaming\NCH Software
2014-04-29 01:30:19 ----D---- C:\Program Files\NCH Software
2014-04-29 01:26:50 ----D---- C:\temp
2014-04-29 01:13:13 ----D---- C:\Program Files\Yawcam

======List of files/folders modified in the last 1 month======

2014-05-26 11:01:52 ----D---- C:\Program Files\trend micro
2014-05-26 11:01:49 ----D---- C:\Windows\Temp
2014-05-26 11:01:08 ----D---- C:\Users\fleker\AppData\Roaming\uTorrent
2014-05-26 11:00:34 ----SHD---- C:\Windows\Installer
2014-05-26 11:00:25 ----D---- C:\Windows\system32\config
2014-05-26 10:50:57 ----SHD---- C:\System Volume Information
2014-05-26 10:50:16 ----D---- C:\Windows\Tasks
2014-05-26 10:50:16 ----D---- C:\Windows\system32\Tasks
2014-05-26 10:49:43 ----D---- C:\Windows\System32
2014-05-26 10:44:53 ----D---- C:\Windows\inf
2014-05-26 10:44:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-05-26 10:39:17 ----AD---- C:\ProgramData\TEMP
2014-05-26 10:37:41 ----D---- C:\Users\fleker\AppData\Roaming\vlc
2014-05-26 02:13:40 ----HD---- C:\ProgramData
2014-05-26 02:13:32 ----D---- C:\Windows\system32\catroot2
2014-05-26 02:12:48 ----D---- C:\Windows\winsxs
2014-05-26 02:12:33 ----D---- C:\Windows\system32\drivers
2014-05-26 02:12:33 ----D---- C:\Windows\L2Schemas
2014-05-26 02:11:46 ----D---- C:\Windows\system32\wbem
2014-05-26 02:11:46 ----D---- C:\Windows\system32\en-US
2014-05-26 02:11:46 ----D---- C:\Windows\system32\drivers\en-US
2014-05-26 02:11:46 ----D---- C:\Windows\system32\cs-CZ
2014-05-26 02:11:46 ----D---- C:\Windows\PolicyDefinitions
2014-05-26 02:11:45 ----D---- C:\Windows\system32\DriverStore
2014-05-25 22:00:26 ----D---- C:\Program Files
2014-05-25 17:34:51 ----D---- C:\Windows\system32\catroot
2014-05-25 16:57:23 ----D---- C:\Windows
2014-05-25 14:04:59 ----D---- C:\Program Files\Lark Anti-Spyware
2014-05-25 13:30:30 ----D---- C:\Program Files\Common Files
2014-05-21 22:10:38 ----D---- C:\Users\fleker\AppData\Roaming\Media Player Classic
2014-05-21 21:08:21 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-05-21 18:03:33 ----D---- C:\Program Files\Mozilla Firefox
2014-05-21 12:35:21 ----D---- C:\Users\fleker\AppData\Roaming\dvdcss
2014-05-18 19:46:06 ----D---- C:\Users\fleker\AppData\Roaming\DAEMON Tools Lite
2014-05-18 19:45:00 ----A---- C:\Windows\system32\RTNUninst32.dll
2014-05-18 19:43:21 ----A---- C:\Windows\system32\atiuxpag.dll
2014-05-18 19:43:21 ----A---- C:\Windows\system32\atiumdva.dll
2014-05-18 19:43:20 ----A---- C:\Windows\system32\atiumdag.dll
2014-05-18 19:43:20 ----A---- C:\Windows\system32\atiu9pag.dll
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atiesrxx.exe
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atieclxx.exe
2014-05-18 19:43:19 ----A---- C:\Windows\system32\atidxx32.dll
2014-05-18 19:43:18 ----A---- C:\Windows\system32\atidemgy.dll
2014-05-18 19:43:18 ----A---- C:\Windows\system32\aticfx32.dll
2014-05-18 19:43:17 ----A---- C:\Windows\system32\atiadlxx.dll
2014-05-18 19:42:25 ----D---- C:\Windows\system32\RTCOM
2014-05-16 21:07:33 ----D---- C:\Windows\system32\wdi
2014-05-15 11:55:13 ----D---- C:\Windows\rescache
2014-05-15 11:39:39 ----D---- C:\Windows\Microsoft.NET
2014-05-15 11:38:47 ----RSD---- C:\Windows\assembly
2014-05-15 03:07:57 ----D---- C:\ProgramData\Microsoft Help
2014-05-15 03:07:36 ----D---- C:\Windows\system32\MRT
2014-05-15 03:04:17 ----D---- C:\Windows\debug
2014-05-15 03:04:13 ----A---- C:\Windows\system32\MRT.exe
2014-05-04 18:29:52 ----D---- C:\Windows\Logs
2014-05-04 18:18:52 ----D---- C:\Users\fleker\AppData\Roaming\Common
2014-05-01 04:31:32 ----D---- C:\Program Files\Opera
2014-05-01 02:02:54 ----D---- C:\Program Files\Noël Danjou
2014-04-30 19:45:35 ----D---- C:\Program Files\Internet Explorer
2014-04-30 08:03:47 ----A---- C:\Windows\win.ini
2014-04-30 03:16:39 ----D---- C:\Users\fleker\AppData\Roaming\Audacity
2014-04-27 23:56:33 ----D---- C:\Program Files\RebelBetting

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 asahci32;asahci32; C:\Windows\system32\DRIVERS\asahci32.sys [2013-01-10 40344]
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-03-09 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-03-09 180248]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-12-24 18624]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2014-03-09 79720]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2014-03-09 775952]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2014-03-09 410784]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2014-04-16 20072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2014-04-16 607168]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2014-04-16 43728]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-01 242240]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2014-04-16 92656]
R1 Spyshelter;Spyshelter; \??\C:\Program Files\SpyShelter Personal Free\SpyShelter.sys [2014-02-13 358240]
R2 AODDriver4.2;AODDriver4.2; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [2012-04-09 48256]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2014-03-09 67824]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 sbapifs;sbapifs; C:\Windows\system32\DRIVERS\sbapifs.sys [2014-01-22 66344]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-05-18 11527680]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-05-18 501248]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2014-03-09 64168]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2014-05-18 77312]
R3 FileMonitor;FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2013-03-23 21480]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2014-05-18 3017112]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 RegFilter;RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2013-11-19 32288]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2014-05-18 693464]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0); C:\Windows\system32\DRIVERS\rusb3hub.sys [2012-08-27 91016]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0); C:\Windows\system32\DRIVERS\rusb3xhc.sys [2012-08-27 181128]
R3 UrlFilter;UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2013-11-19 20944]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 45736]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 gfiark;gfiark; C:\Windows\system32\drivers\gfiark.sys [2013-05-23 43368]
S3 glavcam;BW Microscope; C:\Windows\system32\DRIVERS\glavcam.sys [2014-05-25 64384]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 MSICDSetup;MSICDSetup; \??\D:\CDriver.sys []
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\D:\NTIOLib.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2014-05-25 14848]
S3 sbhips;sbhips; C:\Windows\system32\drivers\sbhips.sys []
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2014-05-25 49664]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 winusb;Služba WinUSB; C:\Windows\system32\DRIVERS\WinUSB.SYS [2010-11-20 35968]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [2014-01-14 881952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-05-18 209408]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-12-19 291840]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-03-09 50344]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2014-04-16 5306504]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2014-01-24 342336]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 UTSvcManager3;UnThreat Service Manager; C:\Program Files\UnThreat AntiVirus\utsvc.exe [2014-01-22 2808112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-30 116648]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-03 2151200]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2014-03-25 1663192]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-05-30 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-03-06 108032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-29 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-05-31 1343400]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Maglajs v prohlížeči

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Shortcut Cleaner http://www.bleepingcomputer.com/downloa ... t-cleaner/
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Spustte tradicne dvouklikem
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v miste spusteni jako sc-cleaner.txt, ten sem vlozte
:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

fleker
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 18 Srp 2013 20:53

Re: Maglajs v prohlížeči

#3 Příspěvek od fleker »

Shortcut Cleaner 1.3.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/

Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 05/27/2014 02:50:00 PM.

Scanning for registry hijacks:

* No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Users\fleker\AppData\Roaming\Microsoft\Windows\Start Menu\

Searching C:\ProgramData\Microsoft\Windows\Start Menu\

Searching C:\Users\fleker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\

Searching C:\Users\Public\Desktop\

Searching C:\Users\fleker\Desktop


0 bad shortcuts found.

Program finished at: 05/27/2014 02:50:07 PM
Execution time: 0 hours(s), 0 minute(s), and 7 seconds(s)
------------------------------------------------------------------------
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by fleker on Łt 27.05.2014 at 14:52:24,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\1clickdownload
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\KMPAskPIPCount_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\KMPAskPIPCount_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_hamachi (1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_hamachi (1)_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{5D43212F-240D-4FE7-92F2-48AC507BA855}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\adtrustmedia"
Successfully deleted: [Folder] "C:\ProgramData\drivergenius"
Successfully deleted: [Folder] "C:\Users\fleker\AppData\Roaming\isafe"
Successfully deleted: [Folder] "C:\Users\fleker\AppData\Roaming\software informer"
Successfully deleted: [Folder] "C:\Program Files\adtrustmedia"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver genius"



~~~ FireFox

Successfully deleted: [File] C:\Users\fleker\AppData\Roaming\mozilla\firefox\profiles\uuy52ycx.default\extensions\gophoto@gophoto.it.xpi
Successfully deleted: [Folder] C:\Users\fleker\AppData\Roaming\mozilla\firefox\profiles\uuy52ycx.default\extensions\savingsslider@mybrowserbar.com
Successfully deleted the following from C:\Users\fleker\AppData\Roaming\mozilla\firefox\profiles\uuy52ycx.default\prefs.js

user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.name", "HDvid-Codec V9.0");
user_pref("extensions.crossrider.bic", "1461f860b5a50f493eb8d9c78f8afe40");



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 27.05.2014 at 15:32:40,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-----------------------------------------------------------------
-----------------------------------------------------------------
-----------------------------------------------------------------
# AdwCleaner v3.211 - Report created 27/05/2014 at 16:58:23
# Updated 26/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : fleker - FLEKER-PC
# Running from : Q:\Downloads\adwcleaner_3.211.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[#] Folder Deleted : C:\ProgramData\BitGuard
[#] Folder Deleted : C:\ProgramData\Browser Manager
[#] Folder Deleted : C:\ProgramData\BrowserProtect
Folder Deleted : C:\ProgramData\IePluginService
Folder Deleted : C:\ProgramData\systemk
Folder Deleted : C:\ProgramData\WPM
Folder Deleted : C:\Program Files\HDvidCodec.com
Folder Deleted : C:\Program Files\Settings Manager
Folder Deleted : C:\Program Files\SupTab
Folder Deleted : C:\Users\berry\AppData\LocalLow\SearchMe
Folder Deleted : C:\Users\fleker\AppData\Roaming\eCyber
Folder Deleted : C:\Users\fleker\AppData\Roaming\SupTab
Folder Deleted : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\Extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}
Folder Deleted : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\Extensions\quick_start@gmail.com
Folder Deleted : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\Extensions\WebSiteRecommendation@weliketheweb.com
Folder Deleted : C:\Users\berry\AppData\Roaming\Mozilla\Firefox\Profiles\9qut6kou.default\Extensions\fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
Folder Deleted : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\Extensions\fca3238e-0f52-4634-8e93-c36d211b2ea9@c1c012cf-93b0-488e-a2c5-453d23bec199.com
Folder Deleted : C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Folder Deleted : C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi
Folder Deleted : C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Deleted : C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Deleted : C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
File Deleted : C:\Users\fleker\daemonprocess.txt
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\qone8.xml
File Deleted : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
File Deleted : C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage
File Deleted : C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com]
Key Deleted : HKCU\Software\Google\Chrome\Extensions\cmaiofennmphjldldcpphcechfnnohja
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F1A63078-3874-4051-9101-D10A0052365E}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1A63078-3874-4051-9101-D10A0052365E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\bi_client_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatequalitink_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatequalitink_RASMANCS
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Software
Key Deleted : HKCU\Software\SystemK
Key Deleted : HKCU\Software\AppDataLow\Software
Key Deleted : HKLM\Software\qone8Software
Key Deleted : HKLM\Software\SupTab
Key Deleted : HKLM\Software\supWPM
Key Deleted : HKLM\Software\SystemK
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rjatydimofu.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v25.0 (cs)

[ File : C:\Users\berry\AppData\Roaming\Mozilla\Firefox\Profiles\9qut6kou.default\prefs.js ]


[ File : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]


[ File : C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaultenginename", "qone8");
Line Deleted : user_pref("browser.search.order.1", "default-search.net");
Line Deleted : user_pref("browser.search.selectedEngine", "qone8");

-\\ Google Chrome v27.0.1453.116

[ File : C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://spokojenypes.cz/inshop/scripts/shop.aspx?action=dosearch&searchphrase={searchTerms}
Deleted [Extension] : cmaiofennmphjldldcpphcechfnnohja
Deleted [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Deleted [Extension] : hbcennhacfaagdopikcegfcobcadeocj
Deleted [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Deleted [Extension] : icdlfehblmklkikfigmjhbmmpmkmpooj
Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Deleted [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Deleted [Extension] : pfndaklgolladniicklehhancnlgocpp
Deleted [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc

[ File : C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.sweetim.com/search.asp?q={searchTerms}&ln=en&src=95&ptr=100&barid=%7B841c978e-c9d5-11e2-aa22-d43d7e547634%7D&sf=0
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&b ... &as=0&ac=0
Deleted [Search Provider] : hxxp://herbio.inshop.cz/inshop/scripts/shop.aspx?action=dosearch&searchphrase={searchTerms}
Deleted [Search Provider] : hxxp://nakup.itesco.cz/cs-CZ/Search/List?searchQuery={searchTerms}&Hledat=Hledat
Deleted [Search Provider] : hxxp://www.default-search.net/search?sid=&aid= ... earchTerms}
Deleted [Search Provider] : hxxp://www.qone8.com/web/?type=ds&ts=140068818 ... earchTerms}
Deleted [Startup_urls] : hxxp://www.default-search.net?sid=&aid=&itype= ... m=&src=hmp
Deleted [Extension] : cmaiofennmphjldldcpphcechfnnohja
Deleted [Extension] : dgpdioedihjhncjafcpgbbjdpbbkikmi
Deleted [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Deleted [Extension] : hbcennhacfaagdopikcegfcobcadeocj
Deleted [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Deleted [Extension] : icdlfehblmklkikfigmjhbmmpmkmpooj
Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Deleted [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Deleted [Extension] : mhkaekfpcppmmioggniknbnbdbcigpkk
Deleted [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma
Deleted [Extension] : pfndaklgolladniicklehhancnlgocpp
Deleted [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc

*************************

AdwCleaner[R0].txt - [11208 octets] - [27/05/2014 16:01:32]
AdwCleaner[S0].txt - [10452 octets] - [27/05/2014 16:58:23]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10513 octets] ##########
Naposledy upravil(a) vyosek dne 28 Kvě 2014 05:52, celkem upraveno 1 x.
Důvod: Odstranena citace odpovedi

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Maglajs v prohlížeči

#4 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

fleker
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 18 Srp 2013 20:53

Re: Maglajs v prohlížeči

#5 Příspěvek od fleker »

vyosek napsal::arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Po spuštění souboru se žádné okno neotevře. Navíc od té doby co jsem ho spustil mi jede větráček od procesoru naplno a je i 100% vytížení paměti.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Maglajs v prohlížeči

#6 Příspěvek od vyosek »

:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

fleker
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 18 Srp 2013 20:53

Re: Maglajs v prohlížeči

#7 Příspěvek od fleker »

Tak už se mi to podařilo, ale zmizely i všechny rozšíření v Google Chrome a i lišta záložek.
---------------------------


Zoek.exe v5.0.0.0 Updated 22-05-2014
Tool run by fleker on źt 29.05.2014 at 3:37:20,16.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\fleker\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-05-29-013005.log 1291 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DC06F773-51BB-4ED1-A4C6-A487E4B22FC2} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{7F6AFBF1-E065-4627-A2FD-810366367D01} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511131156} deleted successfully
HKEY_USERS\S-1-5-21-2860077999-920603677-2990381230-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\berry\AppData\Roaming\Mozilla\Firefox\Profiles\9qut6kou.default\prefs.js:

Added to C:\Users\berry\AppData\Roaming\Mozilla\Firefox\Profiles\9qut6kou.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js:
user_pref("browser.search.defaultenginename", "Yahoo!");

Added to C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\prefs.js:

Added to C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\berry\AppData\Roaming\Mozilla\Firefox\Profiles\9qut6kou.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_29.05.2014_0501_.backup

ProfilePath: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_29.05.2014_0501_.backup

ProfilePath: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default

---- Lines spigot removed from prefs.js ----
user_pref("startpage.ntsearch_url", "http://search.yahoo.com/search?fr=spigo ... earchTerms}");
---- Lines gophoto.it modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST So
---- Lines mybrowserbar modified from prefs.js ----

user_pref("extensions.enabledAddons", "WebSiteRecommendation%40weliketheweb.com:1.0.6,%7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.21,savingsslider%
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST So
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- Lines afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356 removed from prefs.js ----
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.active", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.addressbar", "NA");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.addressbarenhanced", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb.was_copied", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb_dbWasSet", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb.was_copied", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb_dbWasSet", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.backgroundver", 2);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.certdomaininstaller", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.au.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.au.value", "%222014-5-21%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:0
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.cnt.value", "%22CZ%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.first_run.expiration", "Fri Feb 01 2030 0
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.first_run.value", "%221%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.install.expiration", "Fri Feb 01 2030 00:
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.install.value", "%222014-5-21%22");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallationTime.value", "%221396911762%2
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.description", "HDVid Codec - Enjoy the future of
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.domain", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.enablesearch", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.homepage", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.changeprevious", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.iframe", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.InstallationThankYouPage", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.InstallationTime", 1396911762);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.__defualt_browser__.value", "%22ch%22
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_appVer.value", "70");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_nextCheck.expiration", "Thu
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.lastDailyReport", "1400688218564");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.lastUpdate", "1400688215051");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.manifesturl", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.newtab", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.opensearch", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.pluginsurl", "http://js.clientstatsservice.com/p
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.pluginsversion", 65);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.publisher", "installdaddy");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.searchstatus", 0);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.setnewtab", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.thankyou", "");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.updateinterval", 360);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.51356.ver", 70);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.apps", "51356");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.bic", "1461f860b5a50f493eb8d9c78f8afe40");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.cid", 51356);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.firstrun", false);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.hadappinstalled", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.installationdate", 1400688217);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.modetype", "production");
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.reportInstall", true);
user_pref("extensions.afca3238e0f5246348e93c36d211b2ea9c1c012cf93b0488ea2c5453d23bec199com51356.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----

user_29.05.2014_0501_.backup
prefs_29.05.2014_0501_.backup

==== Deleting Files \ Folders ======================

C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\extensions\savingsslider@mybrowserbar.com not found
C:\PROGRA~2\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted
C:\Users\fleker\.android deleted
C:\Users\fleker\AppData\Roaming\Common deleted
C:\PROGRA~2\ProductData deleted
C:\Users\fleker\AppData\Local\Microsoft Research deleted
C:\Users\fleker\AppData\Local\cache deleted
C:\Users\fleker\AppData\LocalLow\ADSRemoval deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default\searchplugins\default-search.xml deleted
"C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\searchme@mybrowserbar.com" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [09.03.2014 04:10]

==== Firefox Extensions ======================

ProfilePath: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
- Advanced SystemCare Surfing Protection - %ProfilePath%\extensions\ascsurfingprotection@iobit.com

ProfilePath: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default
- Undetermined - C:\Program Files\IObit Apps Toolbar\FF
- Advanced SystemCare Surfing Protection - %ProfilePath%\extensions\ascsurfingprotection@iobit.com
- Linkey for Firefox - %ProfilePath%\extensions\extension@linkeyproject.com
- Settings Manager - %ProfilePath%\extensions\{12DC3319-1C0A-106A-C0A9-19AC078CABBB}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- PrivDog - %ProfilePath%\extensions\PrivDog@AdTrustMedia.com.xpi

ExtDir: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
- HDvid Codec - %ExtDir%\hdvc@hdvc.com.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\uuy52ycx.default
785105A23650755A8F7A72405EB0D923 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll - Google Update
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
AC987EE8037531807C5D7E6217A23501 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
A9191AE22A8F1287B5E2DF33E3A57253 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U51
9B10927CFD0F7AD39E40C0E34005B1AD - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.510.13


==== Deleted Firefox Extensions ======================

C:\Users\fleker\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\hdvc@hdvc.com.xpi deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[09.03.2014 04:10]

avast Online Security - berry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Ask Toolbar - fleker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko
Comodo Web Inspector - fleker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn
HDvid-Codec V9.0 - fleker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\iilfecopjcmjdgfffklfdkhbkpkmcglh
Google Translate - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb
Advanced SystemCare Surfing Protection - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmegnmpleoagolcnjnejdacakedpcgd
History 2 - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahejgbbfgmlmjgdjlibphdjeldhagkp
AdBlock - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Linkclump - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj
Google Dictionary (by Google) - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja
Context Menu Search - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocpcmghnefmdhljkoiapafejjohldoga
Auto Refresh Plus - fleker\AppData\Local\Google\Chrome\User Data\Default\Extensions\oilipfekkmncanaajkapbpancpelijih

==== Chrome Fix ======================

C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hamachi.en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_hamachi.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc-performer.en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc-performer.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vocal-remover-plug-in.en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vocal-remover-plug-in.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wave-to-text-v5-2.en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wave-to-text-v5-2.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_yogen-vocal-remover.en.softonic.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_yogen-vocal-remover.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.similarsitesearch.com_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.similarsitesearch.com_0.localstorage-journal deleted successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko deleted successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage deleted successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage-journal deleted successfully
C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Extensions\iilfecopjcmjdgfffklfdkhbkpkmcglh deleted successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\iilfecopjcmjdgfffklfdkhbkpkmcglh deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{33BB0A4E-99AF-4226-BDF6-49120163DE86} qone8 Url="http://www.qone8.com/web/?type=ds&ts=14 ... earchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"

==== Reset Google Chrome ======================

C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Preferences was reset successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Web Data was reset successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\Users\berry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\fleker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\fleker\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\berry\AppData\Local\Mozilla\Firefox\Profiles\9qut6kou.default\Cache emptied successfully
C:\Users\fleker\AppData\Local\Mozilla\Firefox\Profiles\uuy52ycx.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\berry\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\fleker\AppData\Local\Comodo\Dragon\User Data\Default\Cache emptied successfully
C:\Users\fleker\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=360 folders=108 2794798 bytes)

==== Empty Temp Folders ======================

C:\Users\berry\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\fleker\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\fleker\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on źt 29.05.2014 at 17:39:01,36 ======================

fleker
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 18 Srp 2013 20:53

Re: Maglajs v prohlížeči

#8 Příspěvek od fleker »

Navíc mi teď žádné rozšíření do prohlížeče nejde přidat, pořád vyskakuje tato hláška http://oi58.tinypic.com/21ech6r.jpg a taky nefunguje načítání dříve zavřených stránek.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: Maglajs v prohlížeči

#9 Příspěvek od vyosek »

Zkuste reinstal prohlizece
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět