Hromada reklam všude a pořád
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Hromada reklam všude a pořád
Dobrý den, moc prosím o pomoc, děje se mi to, co koukám mnoha dalším lidem, vyskakují reklamy po desítkách... Přikládám log z FRST, snad je správně (mám původně 64-bit, ale z nějakého důvodu přeinstalován na 32-bit, tak jsem stáhla FRST pro 32...):
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014
Ran by romana (administrator) on ROMANA-PC on 29-08-2014 09:37:12
Running from C:\Users\romana\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSrv.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\KMPService.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
(TorchMedia Inc.) C:\Users\romana\AppData\Local\Torch\Update\TorchCrashHandler.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(PlusHDv1.9) C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-nova.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Western Digital) C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Insight Software Solutions) C:\Program Files\ShortKeys2\shklite.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(PlusHDv1.9) C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-bg.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_14_0_0_145_ActiveX.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft2.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft3.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-26] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1667164 2012-09-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2408176 2013-01-10] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [Nástroj WD Drive Unlocker] => C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [1688008 2012-06-13] (Western Digital)
HKLM\...\Run: [Nástroj WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5235128 2012-06-14] (Western Digital Technologies, Inc.)
HKLM\...\Run: [DriveUtilitiesHelper] => C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2774936 2014-05-14] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3681688 2014-05-14] (Crawler.com)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [NextLive] => C:\Windows\system32\rundll32.exe "C:\Users\romana\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
ShortcutTarget: ShortKeys Lite.lnk -> C:\Program Files\ShortKeys2\shklite.exe (Insight Software Solutions)
HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://samoobsluha.mobil.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.dogpile.com/search/web?fcoid ... earchTerms}
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... earchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.dogpile.com/search/web?fcoid ... earchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTe ... l&tsp=5341
SearchScopes: HKCU - {C1947DB3-022F-47B8-95AA-E9706A684020} URL =
SearchScopes: HKCU - {C3409173-75BB-4D7F-B625-6CBD6DAF5D14} URL = http://www.buenosearch.com/?babsrc=SP_k ... rms}&r=169
BHO: PlusHD-V1.9 -> {11111111-1111-1111-1111-110511951170} -> C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-bho.dll (PlusHDv1.9)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
FF NewTab: user_pref("browser.newtab.url", "");
FF DefaultSearchEngine: Search The Web (buenosearch)
FF SelectedSearchEngine: Search The Web (buenosearch)
FF Homepage: https://www.google.cz/?gfe_rd=cr&ei=Ljj ... gws_rd=ssl
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll ()
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll ()
FF SearchPlugin: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\searchplugins\ividi.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Plus-HD-V1.9c - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com [2014-08-29]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-11-18]
FF Extension: PlusHD-V1.9 - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\3446275a-5477-4d33-bd0d-44b466c519cd@4bf28e24-5833-4fb8-88c3-cd8403bb6141.com [2014-08-25]
FF Extension: NoScript - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-14]
FF HKLM\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
FF Extension: Rich Media Player extension - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B} [2013-09-11]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
CHR StartupUrls: Default -> "hxxp://www.idnes.cz/", "hxxp://www.meteocentrum.cz/predpoved-pocasi/cz/6250/praha", "hxxp://eserial.cz/2-broke-yyx/novinky", "hxxp://www.default-search.net?sid=476&aid=113& ... 97&src=hmp", "hxxp://www.buenosearch.com/?babsrc=HP_kms&affI ... 8&tsp=5341"
CHR DefaultSearchKeyword: Default -> buenosearch
CHR DefaultSearchProvider: Default -> buenosearch
CHR DefaultSearchURL: Default -> http://www.buenosearch.com/?babsrc=SP_k ... earchTerms}
CHR DefaultSuggestURL: Default ->
CHR CustomProfile: C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-11]
CHR Extension: (Disk Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-11]
CHR Extension: (YouTube) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-11]
CHR Extension: (Adblock Plus) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-11]
CHR Extension: (Vyhledávání Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-11]
CHR Extension: (PlusHD-V1.9) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp [2014-07-08]
CHR Extension: (Download Video) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni [2013-09-11]
CHR Extension: (iVIDI.org plugin) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol [2013-09-23]
CHR Extension: (Torch Share) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2013-09-23]
CHR Extension: (Peněženka Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-11]
CHR Extension: (WebSite Recommendation) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj [2013-10-25]
CHR Extension: (Gmail) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-11]
CHR HKLM\...\Chrome\Extension: [doagiokpgboiomffjfhaiimafndmmpni] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx [2013-07-23]
CHR HKLM\...\Chrome\Extension: [fkcdbkhjcaljlfolhllfneigeepmjfim] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx [2013-02-28]
CHR HKLM\...\Chrome\Extension: [giacfgjdclhnmkacnfbaljbmpnelflol] - C:\Program Files\iVIDI.org plugin\ividiplg.crx [2012-11-05]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\romana\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-09-11]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Program Files\IDT\WDM\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation) [File not signed]
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [585112 2014-05-14] (Crawler.com)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [303186 2012-09-20] (IDT, Inc.) [File not signed]
R2 TorchCrashHandler; C:\Users\romana\AppData\Local\Torch\Update\TorchCrashHandler.exe [1207648 2013-07-30] (TorchMedia Inc.) [File not signed]
R2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1151424 2012-06-14] (Western Digital )
R2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3086336 2012-12-20] (Qualcomm Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826784 2012-11-28] ()
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-06-21] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 09:37 - 2014-08-29 09:38 - 00020632 _____ () C:\Users\romana\Downloads\FRST.txt
2014-08-29 09:37 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Downloads\FRST.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-28 16:41 - 2014-08-28 16:41 - 01066130 _____ () C:\Users\romana\Desktop\designblok vstupenky.rar
2014-08-28 13:36 - 2014-08-28 14:21 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 11:56 - 2014-08-28 17:15 - 00000000 ____D () C:\Users\romana\Desktop\designblok vstupenky
2014-08-28 11:27 - 2014-08-28 11:27 - 00020266 _____ () C:\Users\romana\Desktop\designblok 14.jpg.bmp
2014-08-28 09:28 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 09:28 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:24 - 2014-08-26 18:26 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:48 - 2014-08-23 07:50 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\SimilarAddon
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\ProgramData\DSearchLink
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Program Files\SiteLookup
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 16:59 - 2014-08-15 17:40 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-14 09:54 - 2014-08-23 07:50 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-13 18:26 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-13 18:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 08:40 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 08:40 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 08:40 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-13 08:40 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-13 08:39 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 08:39 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 08:39 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 08:39 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 08:39 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 08:39 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 08:39 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 08:39 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 08:39 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 08:39 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 08:39 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 08:39 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 08:39 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 08:39 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 08:39 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 08:39 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 08:39 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 08:39 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 08:39 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 08:39 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 08:39 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 08:39 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 08:39 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 08:39 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 08:39 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 08:39 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 08:39 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 08:39 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 08:39 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 08:39 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 08:39 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 08:38 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 08:38 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 08:38 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 08:38 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-01 23:25 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 23:25 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 23:25 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 23:25 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 09:38 - 2014-08-29 09:37 - 00020632 _____ () C:\Users\romana\Downloads\FRST.txt
2014-08-29 09:37 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Downloads\FRST.exe
2014-08-29 09:34 - 2014-08-29 09:33 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-29 09:31 - 2014-07-03 18:31 - 00001460 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-7.job
2014-08-29 09:29 - 2013-09-12 09:59 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Skype
2014-08-29 09:18 - 2013-09-10 21:19 - 01788146 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 09:14 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 09:14 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 09:07 - 2014-07-03 18:32 - 00002188 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-4.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001524 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-1.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001436 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5_user.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001416 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001332 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-2.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00003444 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-11.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00002418 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-3.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00001530 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-6.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00000918 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-08-29 09:07 - 2014-03-16 14:40 - 00000000 ____D () C:\Users\romana\AppData\Roaming\newnext.me
2014-08-29 09:07 - 2014-03-13 22:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-29 09:07 - 2013-09-23 09:45 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-08-29 09:06 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 09:06 - 2009-07-14 06:39 - 00050827 _____ () C:\Windows\setupact.log
2014-08-29 09:06 - 2009-07-14 06:33 - 00303720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 20:03 - 2013-09-12 16:21 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 20:02 - 2014-03-13 22:40 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-28 19:56 - 2013-09-17 15:26 - 00000000 ____D () C:\Users\romana\AppData\Roaming\vlc
2014-08-28 19:26 - 2014-07-10 08:28 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-08-28 18:36 - 2014-07-03 18:31 - 00000922 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-08-28 17:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-28 17:15 - 2014-08-28 11:56 - 00000000 ____D () C:\Users\romana\Desktop\designblok vstupenky
2014-08-28 16:41 - 2014-08-28 16:41 - 01066130 _____ () C:\Users\romana\Desktop\designblok vstupenky.rar
2014-08-28 14:21 - 2014-08-28 13:36 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 11:27 - 2014-08-28 11:27 - 00020266 _____ () C:\Users\romana\Desktop\designblok 14.jpg.bmp
2014-08-27 17:34 - 2013-09-10 21:38 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:26 - 2014-08-26 18:24 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 13:25 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-26 09:03 - 2013-09-12 09:59 - 00000000 ____D () C:\ProgramData\Skype
2014-08-25 09:08 - 2013-09-12 11:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\HpUpdate
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:50 - 2014-08-23 07:48 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-23 07:50 - 2014-08-14 09:54 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-23 03:46 - 2014-08-28 09:28 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 09:28 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:10 - 2013-09-11 00:00 - 00000000 ____D () C:\Users\romana\Desktop\moje
2014-08-18 15:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-08-18 09:09 - 2013-09-12 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-08-18 09:09 - 2013-09-12 11:47 - 00000000 ____D () C:\Program Files\HP
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-17 18:45 - 2013-09-11 07:01 - 00134634 _____ () C:\Windows\PFRO.log
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\SimilarAddon
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\ProgramData\DSearchLink
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Program Files\SiteLookup
2014-08-15 17:45 - 2013-09-11 19:07 - 00000000 ____D () C:\Program Files\The KMPlayer
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 17:40 - 2014-08-15 16:59 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-15 10:20 - 2013-09-11 16:24 - 00000582 _____ () C:\Windows\cedt.INI
2014-08-15 09:09 - 2013-09-10 22:41 - 00000000 ____D () C:\Users\romana\Documents\manifesty
2014-08-14 12:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-14 08:58 - 2014-05-06 16:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 08:58 - 2013-09-11 09:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-08-13 18:33 - 2013-09-11 00:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-13 18:30 - 2013-09-11 00:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 10:35 - 2013-09-11 19:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-13 10:24 - 2009-07-14 05:20 - 00000000 ___RD () C:\Program Files (x86)
2014-08-12 10:10 - 2013-09-11 18:47 - 00000000 ____D () C:\Users\romana\AppData\Local\CutePDF Writer
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:54 - 2013-09-23 09:22 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-07 03:43 - 2014-08-13 08:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 03:39 - 2014-08-13 08:38 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-04 16:12 - 2013-09-11 18:59 - 00001212 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
2014-08-04 16:12 - 2013-09-11 18:57 - 00000000 ____D () C:\Program Files\Paint.NET
2014-08-01 01:16 - 2014-08-13 08:39 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\romana\AppData\Local\Temp\KMP_3.9.0.127.exe
C:\Users\romana\AppData\Local\Temp\SimBundD.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-18 15:31
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014
Ran by romana (administrator) on ROMANA-PC on 29-08-2014 09:37:12
Running from C:\Users\romana\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSrv.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\KMPService.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
(TorchMedia Inc.) C:\Users\romana\AppData\Local\Torch\Update\TorchCrashHandler.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(PlusHDv1.9) C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-nova.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Western Digital) C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Insight Software Solutions) C:\Program Files\ShortKeys2\shklite.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(PlusHDv1.9) C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-bg.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_14_0_0_145_ActiveX.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft2.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft3.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-26] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1667164 2012-09-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2408176 2013-01-10] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [Nástroj WD Drive Unlocker] => C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [1688008 2012-06-13] (Western Digital)
HKLM\...\Run: [Nástroj WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5235128 2012-06-14] (Western Digital Technologies, Inc.)
HKLM\...\Run: [DriveUtilitiesHelper] => C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2774936 2014-05-14] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3681688 2014-05-14] (Crawler.com)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [NextLive] => C:\Windows\system32\rundll32.exe "C:\Users\romana\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
ShortcutTarget: ShortKeys Lite.lnk -> C:\Program Files\ShortKeys2\shklite.exe (Insight Software Solutions)
HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\systemk\x64\sysapcrt.dll
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://samoobsluha.mobil.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.dogpile.com/search/web?fcoid ... earchTerms}
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... earchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.dogpile.com/search/web?fcoid ... earchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTe ... l&tsp=5341
SearchScopes: HKCU - {C1947DB3-022F-47B8-95AA-E9706A684020} URL =
SearchScopes: HKCU - {C3409173-75BB-4D7F-B625-6CBD6DAF5D14} URL = http://www.buenosearch.com/?babsrc=SP_k ... rms}&r=169
BHO: PlusHD-V1.9 -> {11111111-1111-1111-1111-110511951170} -> C:\Program Files\PlusHD-V1.9\PlusHD-V1.9-bho.dll (PlusHDv1.9)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
FF NewTab: user_pref("browser.newtab.url", "");
FF DefaultSearchEngine: Search The Web (buenosearch)
FF SelectedSearchEngine: Search The Web (buenosearch)
FF Homepage: https://www.google.cz/?gfe_rd=cr&ei=Ljj ... gws_rd=ssl
FF Keyword.URL: user_pref("keyword.URL", "");
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll ()
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll ()
FF SearchPlugin: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\searchplugins\ividi.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Plus-HD-V1.9c - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com [2014-08-29]
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-11-18]
FF Extension: PlusHD-V1.9 - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\3446275a-5477-4d33-bd0d-44b466c519cd@4bf28e24-5833-4fb8-88c3-cd8403bb6141.com [2014-08-25]
FF Extension: NoScript - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-14]
FF HKLM\...\Firefox\Extensions: [{3DF4B26D-DB19-45DF-962A-6719D071245B}] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}
FF Extension: Rich Media Player extension - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B} [2013-09-11]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp
CHR StartupUrls: Default -> "hxxp://www.idnes.cz/", "hxxp://www.meteocentrum.cz/predpoved-pocasi/cz/6250/praha", "hxxp://eserial.cz/2-broke-yyx/novinky", "hxxp://www.default-search.net?sid=476&aid=113& ... 97&src=hmp", "hxxp://www.buenosearch.com/?babsrc=HP_kms&affI ... 8&tsp=5341"
CHR DefaultSearchKeyword: Default -> buenosearch
CHR DefaultSearchProvider: Default -> buenosearch
CHR DefaultSearchURL: Default -> http://www.buenosearch.com/?babsrc=SP_k ... earchTerms}
CHR DefaultSuggestURL: Default ->
CHR CustomProfile: C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-11]
CHR Extension: (Disk Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-11]
CHR Extension: (YouTube) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-11]
CHR Extension: (Adblock Plus) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-05-11]
CHR Extension: (Vyhledávání Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-11]
CHR Extension: (PlusHD-V1.9) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp [2014-07-08]
CHR Extension: (Download Video) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni [2013-09-11]
CHR Extension: (iVIDI.org plugin) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol [2013-09-23]
CHR Extension: (Torch Share) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2013-09-23]
CHR Extension: (Peněženka Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-11]
CHR Extension: (WebSite Recommendation) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj [2013-10-25]
CHR Extension: (Gmail) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-11]
CHR HKLM\...\Chrome\Extension: [doagiokpgboiomffjfhaiimafndmmpni] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx [2013-07-23]
CHR HKLM\...\Chrome\Extension: [fkcdbkhjcaljlfolhllfneigeepmjfim] - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx [2013-02-28]
CHR HKLM\...\Chrome\Extension: [giacfgjdclhnmkacnfbaljbmpnelflol] - C:\Program Files\iVIDI.org plugin\ividiplg.crx [2012-11-05]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\romana\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-09-11]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Program Files\IDT\WDM\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation) [File not signed]
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [585112 2014-05-14] (Crawler.com)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [303186 2012-09-20] (IDT, Inc.) [File not signed]
R2 TorchCrashHandler; C:\Users\romana\AppData\Local\Torch\Update\TorchCrashHandler.exe [1207648 2013-07-30] (TorchMedia Inc.) [File not signed]
R2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1151424 2012-06-14] (Western Digital )
R2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3086336 2012-12-20] (Qualcomm Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826784 2012-11-28] ()
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-06-21] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 09:37 - 2014-08-29 09:38 - 00020632 _____ () C:\Users\romana\Downloads\FRST.txt
2014-08-29 09:37 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Downloads\FRST.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-28 16:41 - 2014-08-28 16:41 - 01066130 _____ () C:\Users\romana\Desktop\designblok vstupenky.rar
2014-08-28 13:36 - 2014-08-28 14:21 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 11:56 - 2014-08-28 17:15 - 00000000 ____D () C:\Users\romana\Desktop\designblok vstupenky
2014-08-28 11:27 - 2014-08-28 11:27 - 00020266 _____ () C:\Users\romana\Desktop\designblok 14.jpg.bmp
2014-08-28 09:28 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 09:28 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:24 - 2014-08-26 18:26 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:48 - 2014-08-23 07:50 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\SimilarAddon
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\ProgramData\DSearchLink
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Program Files\SiteLookup
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 16:59 - 2014-08-15 17:40 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-14 09:54 - 2014-08-23 07:50 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-13 18:26 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-13 18:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 08:40 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 08:40 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 08:40 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-13 08:40 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-13 08:39 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 08:39 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 08:39 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 08:39 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 08:39 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 08:39 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 08:39 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 08:39 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 08:39 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 08:39 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 08:39 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 08:39 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 08:39 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 08:39 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 08:39 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 08:39 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 08:39 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 08:39 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 08:39 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 08:39 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 08:39 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 08:39 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 08:39 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 08:39 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 08:39 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 08:39 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 08:39 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 08:39 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 08:39 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 08:39 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 08:39 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 08:38 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 08:38 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 08:38 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 08:38 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-01 23:25 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 23:25 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 23:25 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 23:25 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 09:38 - 2014-08-29 09:37 - 00020632 _____ () C:\Users\romana\Downloads\FRST.txt
2014-08-29 09:37 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Downloads\FRST.exe
2014-08-29 09:34 - 2014-08-29 09:33 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-29 09:31 - 2014-07-03 18:31 - 00001460 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-7.job
2014-08-29 09:29 - 2013-09-12 09:59 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Skype
2014-08-29 09:18 - 2013-09-10 21:19 - 01788146 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 09:14 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 09:14 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 09:07 - 2014-07-03 18:32 - 00002188 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-4.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001524 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-1.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001436 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5_user.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001416 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-5.job
2014-08-29 09:07 - 2014-07-03 18:32 - 00001332 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-2.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00003444 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-11.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00002418 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-3.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00001530 _____ () C:\Windows\Tasks\e29193b0-b61f-4d86-ada8-6277dd849368-6.job
2014-08-29 09:07 - 2014-07-03 18:31 - 00000918 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-08-29 09:07 - 2014-03-16 14:40 - 00000000 ____D () C:\Users\romana\AppData\Roaming\newnext.me
2014-08-29 09:07 - 2014-03-13 22:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-29 09:07 - 2013-09-23 09:45 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-08-29 09:06 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 09:06 - 2009-07-14 06:39 - 00050827 _____ () C:\Windows\setupact.log
2014-08-29 09:06 - 2009-07-14 06:33 - 00303720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 20:03 - 2013-09-12 16:21 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-28 20:02 - 2014-03-13 22:40 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-28 19:56 - 2013-09-17 15:26 - 00000000 ____D () C:\Users\romana\AppData\Roaming\vlc
2014-08-28 19:26 - 2014-07-10 08:28 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-08-28 18:36 - 2014-07-03 18:31 - 00000922 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-08-28 17:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-28 17:15 - 2014-08-28 11:56 - 00000000 ____D () C:\Users\romana\Desktop\designblok vstupenky
2014-08-28 16:41 - 2014-08-28 16:41 - 01066130 _____ () C:\Users\romana\Desktop\designblok vstupenky.rar
2014-08-28 14:21 - 2014-08-28 13:36 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 11:27 - 2014-08-28 11:27 - 00020266 _____ () C:\Users\romana\Desktop\designblok 14.jpg.bmp
2014-08-27 17:34 - 2013-09-10 21:38 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:26 - 2014-08-26 18:24 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 13:25 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-26 09:03 - 2013-09-12 09:59 - 00000000 ____D () C:\ProgramData\Skype
2014-08-25 09:08 - 2013-09-12 11:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\HpUpdate
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:50 - 2014-08-23 07:48 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-23 07:50 - 2014-08-14 09:54 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-23 03:46 - 2014-08-28 09:28 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 09:28 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:10 - 2013-09-11 00:00 - 00000000 ____D () C:\Users\romana\Desktop\moje
2014-08-18 15:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-08-18 09:09 - 2013-09-12 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-08-18 09:09 - 2013-09-12 11:47 - 00000000 ____D () C:\Program Files\HP
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-17 18:45 - 2013-09-11 07:01 - 00134634 _____ () C:\Windows\PFRO.log
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\SimilarAddon
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\ProgramData\DSearchLink
2014-08-15 17:48 - 2014-08-15 17:48 - 00000000 ____D () C:\Program Files\SiteLookup
2014-08-15 17:45 - 2013-09-11 19:07 - 00000000 ____D () C:\Program Files\The KMPlayer
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 17:40 - 2014-08-15 16:59 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-15 10:20 - 2013-09-11 16:24 - 00000582 _____ () C:\Windows\cedt.INI
2014-08-15 09:09 - 2013-09-10 22:41 - 00000000 ____D () C:\Users\romana\Documents\manifesty
2014-08-14 12:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-14 08:58 - 2014-05-06 16:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 08:58 - 2013-09-11 09:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-08-13 18:33 - 2013-09-11 00:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-13 18:30 - 2013-09-11 00:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 10:35 - 2013-09-11 19:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-13 10:24 - 2009-07-14 05:20 - 00000000 ___RD () C:\Program Files (x86)
2014-08-12 10:10 - 2013-09-11 18:47 - 00000000 ____D () C:\Users\romana\AppData\Local\CutePDF Writer
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:54 - 2013-09-23 09:22 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-07 03:43 - 2014-08-13 08:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 03:39 - 2014-08-13 08:38 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-04 16:12 - 2013-09-11 18:59 - 00001212 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
2014-08-04 16:12 - 2013-09-11 18:57 - 00000000 ____D () C:\Program Files\Paint.NET
2014-08-01 01:16 - 2014-08-13 08:39 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\romana\AppData\Local\Temp\KMP_3.9.0.127.exe
C:\Users\romana\AppData\Local\Temp\SimBundD.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-18 15:31
==================== End Of Log ============================
Re: Hromada reklam všude a pořád
Zdravim
Odinstalujte Spyware Terminator
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Hromada reklam všude a pořád
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by romana on p 29.08.2014 at 10:16:44,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\nextlive
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\startsearch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\torch.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220522952270}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550555955570}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660566956670}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544954470}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550555955570}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660566956670}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544954470}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C3409173-75BB-4D7F-B625-6CBD6DAF5D14}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\dsearchlink"
Successfully deleted: [Folder] "C:\ProgramData\ibupdaterservice"
Successfully deleted: [Folder] "C:\ProgramData\torchcrashhandler"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\newnext.me"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\similarsites"
Successfully deleted: [Folder] "C:\Users\romana\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Program Files\myfree codec"
Successfully deleted: [Folder] "C:\Program Files\similarsites"
~~~ FireFox
Successfully deleted: [File] C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\user.js
Successfully deleted the following from C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\prefs.js
user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C
user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%
user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%2
user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "1471fd5c89fbed64c7640ef6dd78500a");
Emptied folder: C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\minidumps [16 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\romana\appdata\local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 29.08.2014 at 10:19:59,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.308 - Report created 29/08/2014 at 10:39:37
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : romana - ROMANA-PC
# Running from : C:\Users\romana\Downloads\adwcleaner_3.308.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : torchcrashhandler
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\SiteLookup
Folder Deleted : C:\Program Files\PlusHD-V1.9
Folder Deleted : C:\Users\romana\AppData\Local\genienext
Folder Deleted : C:\Users\romana\AppData\Local\globalUpdate
Folder Deleted : C:\Users\romana\AppData\Local\Mobogenie
Folder Deleted : C:\Users\romana\AppData\Local\torch
Folder Deleted : C:\Users\romana\AppData\Roaming\SimilarAddon
Folder Deleted : C:\Users\romana\AppData\Roaming\SpeedAnalysis2
Folder Deleted : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\3446275a-5477-4d33-bd0d-44b466c519cd@4bf28e24-5833-4fb8-88c3-cd8403bb6141.com
Folder Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj
File Deleted : C:\Users\romana\daemonprocess.txt
File Deleted : C:\Users\romana\AppData\Roaming\speedanalysis.ico
File Deleted : C:\Users\romana\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Torch.lnk
File Deleted : C:\Users\romana\Desktop\Torch.lnk
File Deleted : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\searchplugins\ividi.xml
File Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-1
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-11
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-2
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-3
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-4
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-5
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-5_user
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-6
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\iLivid.torrent
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\iLivid.torrent
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{685F23D9-FCFD-475C-B56A-362645945C5A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\iVIDI Plugin
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\AppDataLow\Software\PlusHD-V1.9
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\PlusHD-V1.9
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iVIDI Plugin
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PlusHD-V1.9
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17239
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Search The Web (buenosearch)");
Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web (buenosearch)");
Line Deleted : user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22a[...]
Line Deleted : user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D[...]
Line Deleted : user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.c[...]
Line Deleted : user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Line Deleted : user_pref("extensions.ividi.admin", false);
Line Deleted : user_pref("extensions.ividi.aflt", "3");
Line Deleted : user_pref("extensions.ividi.appId", "{685F23D9-FCFD-475C-B56A-362645945C5A}");
Line Deleted : user_pref("extensions.ividi.autoRvrt", "false");
Line Deleted : user_pref("extensions.ividi.dfltLng", "");
Line Deleted : user_pref("extensions.ividi.excTlbr", true);
Line Deleted : user_pref("extensions.ividi.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.ividi.id", "2611878000000000000022df9ad41668");
Line Deleted : user_pref("extensions.ividi.instlDay", "15971");
Line Deleted : user_pref("extensions.ividi.instlRef", "");
Line Deleted : user_pref("extensions.ividi.newTab", false);
Line Deleted : user_pref("extensions.ividi.prdct", "ividi");
Line Deleted : user_pref("extensions.ividi.prtnrId", "ividi");
Line Deleted : user_pref("extensions.ividi.rvrt", "false");
Line Deleted : user_pref("extensions.ividi.smplGrp", "none");
Line Deleted : user_pref("extensions.ividi.tlbrId", "base");
Line Deleted : user_pref("extensions.ividi.tlbrSrchUrl", "hxxp://search.ividi.org/?src=tbsp&id=2611878000000000000022df9ad41668&affilt=3&q=");
Line Deleted : user_pref("extensions.ividi.vrsn", "1.8.23.0");
Line Deleted : user_pref("extensions.ividi.vrsnTs", "1.8.23.09:25:56");
Line Deleted : user_pref("extensions.ividi.vrsni", "1.8.23.0");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Startup_urls] : hxxp://www.default-search.net?sid=476&aid=113& ... 97&src=hmp
Deleted [Startup_urls] : hxxp://www.buenosearch.com/?babsrc=HP_kms&affI ... 8&tsp=5341
Deleted [Extension] : olakgnkoldmagdblaalodobkmeokmgjj
*************************
AdwCleaner[R0].txt - [11952 octets] - [29/08/2014 10:34:58]
AdwCleaner[S0].txt - [12077 octets] - [29/08/2014 10:39:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12138 octets] ##########
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by romana on p 29.08.2014 at 10:16:44,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\nextlive
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\startsearch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\torch.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0059570.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220522952270}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550555955570}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660566956670}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544954470}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0059570.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550555955570}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660566956670}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544954470}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951170}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C3409173-75BB-4D7F-B625-6CBD6DAF5D14}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\dsearchlink"
Successfully deleted: [Folder] "C:\ProgramData\ibupdaterservice"
Successfully deleted: [Folder] "C:\ProgramData\torchcrashhandler"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\newnext.me"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\romana\AppData\Roaming\similarsites"
Successfully deleted: [Folder] "C:\Users\romana\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Program Files\myfree codec"
Successfully deleted: [Folder] "C:\Program Files\similarsites"
~~~ FireFox
Successfully deleted: [File] C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\user.js
Successfully deleted the following from C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\prefs.js
user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C
user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%
user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%2
user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "1471fd5c89fbed64c7640ef6dd78500a");
Emptied folder: C:\Users\romana\AppData\Roaming\mozilla\firefox\profiles\egp7tx79.default\minidumps [16 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\romana\appdata\local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 29.08.2014 at 10:19:59,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.308 - Report created 29/08/2014 at 10:39:37
# Updated 20/08/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : romana - ROMANA-PC
# Running from : C:\Users\romana\Downloads\adwcleaner_3.308.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : torchcrashhandler
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\SiteLookup
Folder Deleted : C:\Program Files\PlusHD-V1.9
Folder Deleted : C:\Users\romana\AppData\Local\genienext
Folder Deleted : C:\Users\romana\AppData\Local\globalUpdate
Folder Deleted : C:\Users\romana\AppData\Local\Mobogenie
Folder Deleted : C:\Users\romana\AppData\Local\torch
Folder Deleted : C:\Users\romana\AppData\Roaming\SimilarAddon
Folder Deleted : C:\Users\romana\AppData\Roaming\SpeedAnalysis2
Folder Deleted : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\3446275a-5477-4d33-bd0d-44b466c519cd@4bf28e24-5833-4fb8-88c3-cd8403bb6141.com
Folder Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj
File Deleted : C:\Users\romana\daemonprocess.txt
File Deleted : C:\Users\romana\AppData\Roaming\speedanalysis.ico
File Deleted : C:\Users\romana\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Torch.lnk
File Deleted : C:\Users\romana\Desktop\Torch.lnk
File Deleted : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\searchplugins\ividi.xml
File Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-1
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-11
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-2
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-3
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-4
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-5
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-5_user
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-6
Task Deleted : e29193b0-b61f-4d86-ada8-6277dd849368-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\iLivid.torrent
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\iLivid.torrent
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{685F23D9-FCFD-475C-B56A-362645945C5A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\iVIDI Plugin
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\AppDataLow\Software\PlusHD-V1.9
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\PlusHD-V1.9
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iVIDI Plugin
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PlusHD-V1.9
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17239
-\\ Mozilla Firefox v31.0 (x86 cs)
[ File : C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Search The Web (buenosearch)");
Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web (buenosearch)");
Line Deleted : user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.co.uk%22%2C%22a[...]
Line Deleted : user_pref("extensions.a0b105cbff1eb40b89bca7dae371d7ead239035fb4613ab38efcom61762.61762.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D[...]
Line Deleted : user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.c[...]
Line Deleted : user_pref("extensions.a3446275a54774d33bd0d44b466c519cd4bf28e2458334fb888c3cd8403bb6141com59570.59570.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Line Deleted : user_pref("extensions.ividi.admin", false);
Line Deleted : user_pref("extensions.ividi.aflt", "3");
Line Deleted : user_pref("extensions.ividi.appId", "{685F23D9-FCFD-475C-B56A-362645945C5A}");
Line Deleted : user_pref("extensions.ividi.autoRvrt", "false");
Line Deleted : user_pref("extensions.ividi.dfltLng", "");
Line Deleted : user_pref("extensions.ividi.excTlbr", true);
Line Deleted : user_pref("extensions.ividi.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.ividi.id", "2611878000000000000022df9ad41668");
Line Deleted : user_pref("extensions.ividi.instlDay", "15971");
Line Deleted : user_pref("extensions.ividi.instlRef", "");
Line Deleted : user_pref("extensions.ividi.newTab", false);
Line Deleted : user_pref("extensions.ividi.prdct", "ividi");
Line Deleted : user_pref("extensions.ividi.prtnrId", "ividi");
Line Deleted : user_pref("extensions.ividi.rvrt", "false");
Line Deleted : user_pref("extensions.ividi.smplGrp", "none");
Line Deleted : user_pref("extensions.ividi.tlbrId", "base");
Line Deleted : user_pref("extensions.ividi.tlbrSrchUrl", "hxxp://search.ividi.org/?src=tbsp&id=2611878000000000000022df9ad41668&affilt=3&q=");
Line Deleted : user_pref("extensions.ividi.vrsn", "1.8.23.0");
Line Deleted : user_pref("extensions.ividi.vrsnTs", "1.8.23.09:25:56");
Line Deleted : user_pref("extensions.ividi.vrsni", "1.8.23.0");
-\\ Google Chrome v36.0.1985.143
[ File : C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Startup_urls] : hxxp://www.default-search.net?sid=476&aid=113& ... 97&src=hmp
Deleted [Startup_urls] : hxxp://www.buenosearch.com/?babsrc=HP_kms&affI ... 8&tsp=5341
Deleted [Extension] : olakgnkoldmagdblaalodobkmeokmgjj
*************************
AdwCleaner[R0].txt - [11952 octets] - [29/08/2014 10:34:58]
AdwCleaner[S0].txt - [12077 octets] - [29/08/2014 10:39:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12138 octets] ##########
Re: Hromada reklam všude a pořád
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Hromada reklam všude a pořád
Zoek.exe v5.0.0.0 Updated 28-08-2014
Tool run by romana on p 29.08.2014 at 11:12:40,13.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\romana\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.8.2014 11:13:50 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
Added to C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.cz/?gfe_rd=cr&ei=Ljj ... gws_rd=ssl");
user_pref("browser.newtab.url", "");
user_pref("keyword.URL", "");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js:
Deleted from C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
Added to C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
ProfilePath: C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
==== Deleting Files \ Folders ======================
C:\Users\romana\.android deleted
C:\Program Files\Probit Software deleted
C:\Program Files\iVIDI.org plugin deleted
C:\Program Files\Wise\Wise Registry Cleaner deleted
C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions deleted
C:\Users\romana\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Public\Desktop\Flvto Youtube Downloader.lnk deleted
C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\extensions\0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com deleted
"C:\Users\romana\AppData\Roaming\pdfperformer" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{3DF4B26D-DB19-45DF-962A-6719D071245B}"="C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}" []
==== Firefox Extensions ======================
ProfilePath: C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default
- Undetermined - C:\Users\HP\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
- Visualisateur 3D de 20-20 - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
ProfilePath: C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
14D06C3796CE3F6BA8F43CDF3AD65D76 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U67
0A6E5E3BEF374AA2F47071E7374EAD7B - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.670.1
005EBE4A4E6E9C9A7967F6C3F413C1DF - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
421CB2C1010522B3BF7C00725520B844 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
421CB2C1010522B3BF7C00725520B844 - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll - Adobe Acrobat
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
A32402A7A2AC60B5422255DF020EC44A - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
37BC12D7E076F77D432C74DAAE08A138 - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\extensions\2020Player_IKEA@2020Technologies.com\plugins\NP_2020Player_IKEA.dll - 20-20 3D Viewer for IKEA
86244E1B6D062BBE2B91AA5DA7376806 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
0C0C5C207121C7A78414A8250E8E099A - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director
11D9EC08007CCDD653E6762E289E7C1B - C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll - PluginRichmediaplayer
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
doagiokpgboiomffjfhaiimafndmmpni - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx[]
fkcdbkhjcaljlfolhllfneigeepmjfim - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx[]
giacfgjdclhnmkacnfbaljbmpnelflol - C:\Program Files\iVIDI.org plugin\ividiplg.crx[]
PlusHD-V1.9 - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp
Rich Media Downloader - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni
iVIDI.org plugin - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol
==== Chromium Startpages ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.search.ask.com/?gct=hp",
"homepage": "http://google.com/",
"startup_urls": [ "http://www.idnes.cz/", "http://www.meteocentrum.cz/predpoved-po ... 6250/praha", "http://eserial.cz/2-broke-yyx/novinky", "http://www.default-search.net?sid=476&a ... 97&src=hmp", "http://www.buenosearch.com/?babsrc=HP_k ... 8&tsp=5341" ],
==== Chrome Fix ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0.localstorage deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0.localstorage-journal deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0 deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\djaoeafihpfaakkpdobmhedohgnmhpbp deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{C1947DB3-022F-47B8-95AA-E9706A684020} Unknown Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C1947DB3-022F-47B8-95AA-E9706A684020} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{3DF4B26D-DB19-45DF-962A-6719D071245B} deleted successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\doagiokpgboiomffjfhaiimafndmmpni deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\fkcdbkhjcaljlfolhllfneigeepmjfim deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully
==== Empty IE Cache ======================
C:\Users\romana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\romana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\romana\AppData\Local\Mozilla\Firefox\Profiles\egp7tx79.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=311 folders=52 11615876 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\romana\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\romana\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp" deleted
==== EOF on p 29.08.2014 at 12:12:10,36 ======================
Tool run by romana on p 29.08.2014 at 11:12:40,13.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\romana\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
29.8.2014 11:13:50 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
Added to C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.cz/?gfe_rd=cr&ei=Ljj ... gws_rd=ssl");
user_pref("browser.newtab.url", "");
user_pref("keyword.URL", "");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\prefs.js:
Deleted from C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
Added to C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
ProfilePath: C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_29.08.2014_1124_.backup
==== Deleting Files \ Folders ======================
C:\Users\romana\.android deleted
C:\Program Files\Probit Software deleted
C:\Program Files\iVIDI.org plugin deleted
C:\Program Files\Wise\Wise Registry Cleaner deleted
C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions deleted
C:\Users\romana\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Public\Desktop\Flvto Youtube Downloader.lnk deleted
C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\extensions\0b105cbff1eb40b89bca7dae371d@7ead239035fb4613ab38ef.com deleted
"C:\Users\romana\AppData\Roaming\pdfperformer" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{3DF4B26D-DB19-45DF-962A-6719D071245B}"="C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Firefox\{3DF4B26D-DB19-45DF-962A-6719D071245B}" []
==== Firefox Extensions ======================
ProfilePath: C:\Users\romana\AppData\Local\Thunderbird\Profiles\f08eoo4m.default
- Undetermined - C:\Users\HP\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
- Visualisateur 3D de 20-20 - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
ProfilePath: C:\Users\romana\AppData\Roaming\Thunderbird\Profiles\f08eoo4m.default
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
14D06C3796CE3F6BA8F43CDF3AD65D76 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U67
0A6E5E3BEF374AA2F47071E7374EAD7B - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.670.1
005EBE4A4E6E9C9A7967F6C3F413C1DF - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
421CB2C1010522B3BF7C00725520B844 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
421CB2C1010522B3BF7C00725520B844 - C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll - Adobe Acrobat
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
A32402A7A2AC60B5422255DF020EC44A - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
37BC12D7E076F77D432C74DAAE08A138 - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\extensions\2020Player_IKEA@2020Technologies.com\plugins\NP_2020Player_IKEA.dll - 20-20 3D Viewer for IKEA
86244E1B6D062BBE2B91AA5DA7376806 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
0C0C5C207121C7A78414A8250E8E099A - C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll - Shockwave for Director / Shockwave for Director
11D9EC08007CCDD653E6762E289E7C1B - C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll - PluginRichmediaplayer
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
doagiokpgboiomffjfhaiimafndmmpni - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\richmediadownloader.crx[]
fkcdbkhjcaljlfolhllfneigeepmjfim - C:\Users\romana\AppData\Local\Rich Media Player\BrowserExtensions\Chrome\playerextension.crx[]
giacfgjdclhnmkacnfbaljbmpnelflol - C:\Program Files\iVIDI.org plugin\ividiplg.crx[]
PlusHD-V1.9 - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp
Rich Media Downloader - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni
iVIDI.org plugin - romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol
==== Chromium Startpages ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.search.ask.com/?gct=hp",
"homepage": "http://google.com/",
"startup_urls": [ "http://www.idnes.cz/", "http://www.meteocentrum.cz/predpoved-po ... 6250/praha", "http://eserial.cz/2-broke-yyx/novinky", "http://www.default-search.net?sid=476&a ... 97&src=hmp", "http://www.buenosearch.com/?babsrc=HP_k ... 8&tsp=5341" ],
==== Chrome Fix ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\doagiokpgboiomffjfhaiimafndmmpni deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0.localstorage deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0.localstorage-journal deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_djaoeafihpfaakkpdobmhedohgnmhpbp_0 deleted successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\djaoeafihpfaakkpdobmhedohgnmhpbp deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{C1947DB3-022F-47B8-95AA-E9706A684020} Unknown Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Internet Explorer\SearchScopes\{C1947DB3-022F-47B8-95AA-E9706A684020} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{3DF4B26D-DB19-45DF-962A-6719D071245B} deleted successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\doagiokpgboiomffjfhaiimafndmmpni deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\fkcdbkhjcaljlfolhllfneigeepmjfim deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully
==== Empty IE Cache ======================
C:\Users\romana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\romana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\romana\AppData\Local\Mozilla\Firefox\Profiles\egp7tx79.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=311 folders=52 11615876 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\romana\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\romana\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\djaoeafihpfaakkpdobmhedohgnmhpbp" deleted
==== EOF on p 29.08.2014 at 12:12:10,36 ======================
Re: Hromada reklam všude a pořád
Poprosim o novy log z FRST
Re: Hromada reklam všude a pořád
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014
Ran by romana (administrator) on ROMANA-PC on 29-08-2014 13:26:04
Running from C:\Users\romana\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSrv.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\KMPService.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Western Digital) C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Insight Software Solutions) C:\Program Files\ShortKeys2\shklite.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft2.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft3.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-26] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1667164 2012-09-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2408176 2013-01-10] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [Nástroj WD Drive Unlocker] => C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [1688008 2012-06-13] (Western Digital)
HKLM\...\Run: [Nástroj WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5235128 2012-06-14] (Western Digital Technologies, Inc.)
HKLM\...\Run: [DriveUtilitiesHelper] => C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
ShortcutTarget: ShortKeys Lite.lnk -> C:\Program Files\ShortKeys2\shklite.exe (Insight Software Solutions)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://samoobsluha.mobil.cz/
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... earchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll ()
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-11-18]
FF Extension: NoScript - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-14]
Chrome:
=======
CHR CustomProfile: C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Peněženka Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-11]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Program Files\IDT\WDM\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [303186 2012-09-20] (IDT, Inc.) [File not signed]
R2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1151424 2012-06-14] (Western Digital )
R2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3086336 2012-12-20] (Qualcomm Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826784 2012-11-28] ()
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-06-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 11:27 - 2014-08-29 11:12 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:13 - 2014-08-29 12:12 - 00015236 _____ () C:\zoek-results.log
2014-08-29 11:12 - 2014-08-29 11:25 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:34 - 2014-08-29 10:40 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:15 - 2014-08-29 10:16 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:37 - 2014-08-29 13:26 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Desktop\FRST.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-28 13:36 - 2014-08-28 14:21 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 09:28 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 09:28 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:24 - 2014-08-26 18:26 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:48 - 2014-08-23 07:50 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 16:59 - 2014-08-15 17:40 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-14 09:54 - 2014-08-29 11:24 - 00000000 ____D () C:\Program Files\Wise
2014-08-14 09:54 - 2014-08-23 07:50 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-13 18:26 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-13 18:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 08:40 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 08:40 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 08:40 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-13 08:40 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-13 08:39 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 08:39 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 08:39 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 08:39 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 08:39 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 08:39 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 08:39 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 08:39 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 08:39 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 08:39 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 08:39 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 08:39 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 08:39 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 08:39 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 08:39 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 08:39 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 08:39 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 08:39 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 08:39 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 08:39 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 08:39 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 08:39 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 08:39 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 08:39 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 08:39 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 08:39 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 08:39 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 08:39 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 08:39 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 08:39 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 08:39 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 08:38 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 08:38 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 08:38 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 08:38 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-01 23:25 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 23:25 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 23:25 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 23:25 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 13:26 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 13:25 - 2013-09-12 09:59 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Skype
2014-08-29 13:03 - 2013-09-12 16:21 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-29 13:02 - 2014-03-13 22:40 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-29 12:19 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 12:19 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 12:15 - 2013-09-10 21:19 - 01803781 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 12:12 - 2014-08-29 11:13 - 00015236 _____ () C:\zoek-results.log
2014-08-29 12:11 - 2014-03-13 22:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-29 12:11 - 2013-09-11 07:01 - 00135282 _____ () C:\Windows\PFRO.log
2014-08-29 12:11 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 12:11 - 2009-07-14 06:39 - 00050939 _____ () C:\Windows\setupact.log
2014-08-29 11:25 - 2014-08-29 11:12 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:24 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-29 11:24 - 2013-09-11 19:00 - 00000000 ____D () C:\Users\romana\AppData\Local\Rich Media Player
2014-08-29 11:24 - 2013-09-10 21:35 - 00000000 ____D () C:\Users\romana
2014-08-29 11:12 - 2014-08-29 11:27 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 11:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:40 - 2014-08-29 10:34 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:16 - 2014-08-29 10:15 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Desktop\FRST.exe
2014-08-29 09:34 - 2014-08-29 09:33 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-29 09:06 - 2009-07-14 06:33 - 00303720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 19:56 - 2013-09-17 15:26 - 00000000 ____D () C:\Users\romana\AppData\Roaming\vlc
2014-08-28 14:21 - 2014-08-28 13:36 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-27 17:34 - 2013-09-10 21:38 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:26 - 2014-08-26 18:24 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 13:25 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-26 09:03 - 2013-09-12 09:59 - 00000000 ____D () C:\ProgramData\Skype
2014-08-25 09:08 - 2013-09-12 11:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\HpUpdate
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:50 - 2014-08-23 07:48 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-23 07:50 - 2014-08-14 09:54 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-23 03:46 - 2014-08-28 09:28 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 09:28 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:10 - 2013-09-11 00:00 - 00000000 ____D () C:\Users\romana\Desktop\moje
2014-08-18 15:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-08-18 09:09 - 2013-09-12 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-08-18 09:09 - 2013-09-12 11:47 - 00000000 ____D () C:\Program Files\HP
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:45 - 2013-09-11 19:07 - 00000000 ____D () C:\Program Files\The KMPlayer
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 17:40 - 2014-08-15 16:59 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-15 10:20 - 2013-09-11 16:24 - 00000582 _____ () C:\Windows\cedt.INI
2014-08-15 09:09 - 2013-09-10 22:41 - 00000000 ____D () C:\Users\romana\Documents\manifesty
2014-08-14 12:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 08:58 - 2014-05-06 16:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 08:58 - 2013-09-11 09:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-08-13 18:33 - 2013-09-11 00:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-13 18:30 - 2013-09-11 00:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 10:35 - 2013-09-11 19:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-13 10:24 - 2009-07-14 05:20 - 00000000 ___RD () C:\Program Files (x86)
2014-08-12 10:10 - 2013-09-11 18:47 - 00000000 ____D () C:\Users\romana\AppData\Local\CutePDF Writer
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:54 - 2013-09-23 09:22 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-07 03:43 - 2014-08-13 08:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 03:39 - 2014-08-13 08:38 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-04 16:12 - 2013-09-11 18:59 - 00001212 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
2014-08-04 16:12 - 2013-09-11 18:57 - 00000000 ____D () C:\Program Files\Paint.NET
2014-08-01 01:16 - 2014-08-13 08:39 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-29 11:44
==================== End Of Log ============================
Ran by romana (administrator) on ROMANA-PC on 29-08-2014 13:26:04
Running from C:\Users\romana\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSrv.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\KMPService.exe
(PandoraTV) C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
(Western Digital ) C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Western Digital) C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Insight Software Solutions) C:\Program Files\ShortKeys2\shklite.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files\Mozilla Thunderbird\thunderbird.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft2.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft.exe
(Ticketpro Technologies, a.s.) C:\Ticketsoft\Ticketsoft3.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-26] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [1667164 2012-09-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2408176 2013-01-10] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [Nástroj WD Drive Unlocker] => C:\Program Files\Western Digital\WD Security\WDDriveAutoUnlock.exe [1688008 2012-06-13] (Western Digital)
HKLM\...\Run: [Nástroj WD Quick View] => C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe [5235128 2012-06-14] (Western Digital Technologies, Inc.)
HKLM\...\Run: [DriveUtilitiesHelper] => C:\Program Files\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
ShortcutTarget: ShortKeys Lite.lnk -> C:\Program Files\ShortKeys2\shklite.exe (Insight Software Solutions)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://samoobsluha.mobil.cz/
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... earchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @richmediaplayer.com/nppluginrichmediaplayer -> C:\Program Files\Mozilla Firefox\plugins\nppluginrichmediaplayer.dll ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppluginrichmediaplayer.dll ()
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-11-18]
FF Extension: NoScript - C:\Users\romana\AppData\Roaming\Mozilla\Firefox\Profiles\egp7tx79.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-08-14]
Chrome:
=======
CHR CustomProfile: C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Peněženka Google) - C:\Users\romana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-11]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Program Files\IDT\WDM\aestsrv.exe [81920 2009-03-03] (Andrea Electronics Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV.exe [303186 2012-09-20] (IDT, Inc.) [File not signed]
R2 WDBackup; C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe [1151424 2012-06-14] (Western Digital )
R2 WDDriveService; C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3086336 2012-12-20] (Qualcomm Atheros Communications, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1826784 2012-11-28] ()
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [181912 2013-06-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 11:27 - 2014-08-29 11:12 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:13 - 2014-08-29 12:12 - 00015236 _____ () C:\zoek-results.log
2014-08-29 11:12 - 2014-08-29 11:25 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:34 - 2014-08-29 10:40 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:15 - 2014-08-29 10:16 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:37 - 2014-08-29 13:26 - 00000000 ____D () C:\FRST
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Desktop\FRST.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-28 13:36 - 2014-08-28 14:21 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-28 09:28 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 09:28 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:24 - 2014-08-26 18:26 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:48 - 2014-08-23 07:50 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 16:59 - 2014-08-15 17:40 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-14 09:54 - 2014-08-29 11:24 - 00000000 ____D () C:\Program Files\Wise
2014-08-14 09:54 - 2014-08-23 07:50 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-13 18:26 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-13 18:26 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-13 18:26 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 08:40 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 08:40 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 08:40 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-13 08:40 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-13 08:39 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 08:39 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 08:39 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 08:39 - 2014-07-25 15:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 08:39 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 08:39 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 08:39 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 08:39 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 08:39 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 08:39 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 08:39 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 08:39 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 08:39 - 2014-07-25 14:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 08:39 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 08:39 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 08:39 - 2014-07-25 13:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 08:39 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 08:39 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 08:39 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 08:39 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 08:39 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 08:39 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 08:39 - 2014-07-25 13:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 08:39 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 08:39 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 08:39 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 08:39 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 08:39 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 08:39 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 08:39 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 08:39 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 08:39 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 08:39 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 08:38 - 2014-08-07 03:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 08:38 - 2014-08-07 03:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 08:38 - 2014-07-09 03:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 08:38 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 08:38 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-01 23:25 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 23:25 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 23:25 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 23:25 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 23:25 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 23:25 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 13:26 - 2014-08-29 09:37 - 00000000 ____D () C:\FRST
2014-08-29 13:25 - 2013-09-12 09:59 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Skype
2014-08-29 13:03 - 2013-09-12 16:21 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-29 13:02 - 2014-03-13 22:40 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-29 12:19 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 12:19 - 2009-07-14 06:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 12:15 - 2013-09-10 21:19 - 01803781 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 12:12 - 2014-08-29 11:13 - 00015236 _____ () C:\zoek-results.log
2014-08-29 12:11 - 2014-03-13 22:40 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-29 12:11 - 2013-09-11 07:01 - 00135282 _____ () C:\Windows\PFRO.log
2014-08-29 12:11 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 12:11 - 2009-07-14 06:39 - 00050939 _____ () C:\Windows\setupact.log
2014-08-29 11:25 - 2014-08-29 11:12 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:24 - 2014-08-14 09:54 - 00000000 ____D () C:\Program Files\Wise
2014-08-29 11:24 - 2013-09-11 19:00 - 00000000 ____D () C:\Users\romana\AppData\Local\Rich Media Player
2014-08-29 11:24 - 2013-09-10 21:35 - 00000000 ____D () C:\Users\romana
2014-08-29 11:12 - 2014-08-29 11:27 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 11:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:40 - 2014-08-29 10:34 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:16 - 2014-08-29 10:15 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:36 - 2014-08-29 09:36 - 01095168 _____ (Farbar) C:\Users\romana\Desktop\FRST.exe
2014-08-29 09:34 - 2014-08-29 09:33 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
2014-08-29 09:06 - 2009-07-14 06:33 - 00303720 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 19:56 - 2013-09-17 15:26 - 00000000 ____D () C:\Users\romana\AppData\Roaming\vlc
2014-08-28 14:21 - 2014-08-28 13:36 - 415537828 _____ () C:\Users\romana\Downloads\horrible-bosses-2011-dvdrip-xvid-cz.rar
2014-08-27 17:34 - 2013-09-10 21:38 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-27 15:28 - 2014-08-27 15:28 - 00112107 _____ (forum.viry.cz) C:\Users\romana\Downloads\VerzeOS.exe
2014-08-26 18:26 - 2014-08-26 18:24 - 22631528 _____ () C:\Users\romana\Downloads\The-Big-Bang-Theory-S03---complete.rar
2014-08-26 13:25 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-08-26 09:03 - 2014-08-26 09:03 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-26 09:03 - 2013-09-12 09:59 - 00000000 ____D () C:\ProgramData\Skype
2014-08-25 09:08 - 2013-09-12 11:48 - 00000000 ____D () C:\Users\romana\AppData\Roaming\HpUpdate
2014-08-23 07:50 - 2014-08-23 07:50 - 00151552 _____ () C:\Windows\system32\config\DEFAULT.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00028672 _____ () C:\Windows\system32\config\SAM.rhk
2014-08-23 07:50 - 2014-08-23 07:50 - 00024576 _____ () C:\Windows\system32\config\SECURITY.rhk
2014-08-23 07:50 - 2014-08-23 07:48 - 43753472 _____ () C:\Windows\system32\config\SOFTWARE.rhk
2014-08-23 07:50 - 2014-08-14 09:54 - 00000000 ____D () C:\Users\romana\AppData\Roaming\Wise Registry Cleaner
2014-08-23 03:46 - 2014-08-28 09:28 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 09:28 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:10 - 2013-09-11 00:00 - 00000000 ____D () C:\Users\romana\Desktop\moje
2014-08-18 15:40 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-08-18 09:09 - 2013-09-12 11:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-08-18 09:09 - 2013-09-12 11:47 - 00000000 ____D () C:\Program Files\HP
2014-08-18 09:08 - 2014-08-18 09:08 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-08-15 17:45 - 2013-09-11 19:07 - 00000000 ____D () C:\Program Files\The KMPlayer
2014-08-15 17:41 - 2014-08-15 17:41 - 00074464 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodsterCZ.sub
2014-08-15 17:40 - 2014-08-15 16:59 - 734334976 _____ () C:\Users\romana\Downloads\Notting-Hill-[1999][Eng]DVDRip-woodster.avi
2014-08-15 10:20 - 2013-09-11 16:24 - 00000582 _____ () C:\Windows\cedt.INI
2014-08-15 09:09 - 2013-09-10 22:41 - 00000000 ____D () C:\Users\romana\Documents\manifesty
2014-08-14 12:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-08-14 09:54 - 2014-08-14 09:54 - 00001185 _____ () C:\Users\Public\Desktop\Wise Registry Cleaner.lnk
2014-08-14 09:54 - 2014-08-14 09:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Registry Cleaner
2014-08-14 08:58 - 2014-05-06 16:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-14 08:58 - 2013-09-11 09:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-08-13 18:33 - 2013-09-11 00:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-13 18:30 - 2013-09-11 00:04 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 10:35 - 2014-08-13 10:35 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-13 10:35 - 2013-09-11 19:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-13 10:24 - 2009-07-14 05:20 - 00000000 ___RD () C:\Program Files (x86)
2014-08-12 10:10 - 2013-09-11 18:47 - 00000000 ____D () C:\Users\romana\AppData\Local\CutePDF Writer
2014-08-11 08:54 - 2014-08-11 08:54 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-11 08:54 - 2013-09-23 09:22 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-11 08:53 - 2014-08-11 08:53 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-11 08:53 - 2014-08-11 08:53 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-11 08:53 - 2014-08-11 08:53 - 00000000 ____D () C:\Program Files\Java
2014-08-07 03:43 - 2014-08-13 08:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 03:39 - 2014-08-13 08:38 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-04 16:12 - 2013-09-11 18:59 - 00001212 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
2014-08-04 16:12 - 2013-09-11 18:57 - 00000000 ____D () C:\Program Files\Paint.NET
2014-08-01 01:16 - 2014-08-13 08:39 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-29 11:44
==================== End Of Log ============================
Re: Hromada reklam všude a pořád
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation) HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation) HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung) HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung) HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.) SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... DCD44F4&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... hx?prefix={searchTerms} R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV) C:\Program Files\PANDORA.TV 2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt 2014-08-29 11:27 - 2014-08-29 11:12 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-08-29 11:13 - 2014-08-29 12:12 - 00015236 _____ () C:\zoek-results.log 2014-08-29 11:12 - 2014-08-29 11:25 - 00000000 ____D () C:\zoek_backup 2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe 2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe 2014-08-29 10:34 - 2014-08-29 10:40 - 00000000 ____D () C:\AdwCleaner 2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe 2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT 2014-08-29 10:15 - 2014-08-29 10:16 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe 2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro 2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit 2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe Hosts: Reboot: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: Hromada reklam všude a pořád
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:30-08-2014 01
Ran by romana at 2014-08-31 08:31:37 Run:1
Running from C:\Users\romana\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... DCD44F4&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... hx?prefix={searchTerms}
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
C:\Program Files\PANDORA.TV
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 11:27 - 2014-08-29 11:12 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:13 - 2014-08-29 12:12 - 00015236 _____ () C:\zoek-results.log
2014-08-29 11:12 - 2014-08-29 11:25 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:34 - 2014-08-29 10:40 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:15 - 2014-08-29 10:16 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
Hosts:
Reboot:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KiesTrayAgent => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation) => Value not found.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\KiesPreload => value deleted successfully.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69 => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL http://search.conduit.com/Results.aspx? ... => Value not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... => Value not found.
PanService => Service stopped successfully.
PanService => Service deleted successfully.
C:\Program Files\PANDORA.TV => Moved successfully.
C:\Users\romana\Desktop\FRST.txt => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
"C:\Users\romana\Downloads\zoek.exe" => File/Directory not found.
"C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe" => File/Directory not found.
C:\AdwCleaner => Moved successfully.
"C:\Users\romana\Downloads\adwcleaner_3.308.exe" => File/Directory not found.
C:\Windows\ERUNT => Moved successfully.
"C:\Users\romana\Downloads\JRT.exe" => File/Directory not found.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
"C:\Users\romana\Downloads\RSIT.exe" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====
Ran by romana at 2014-08-31 08:31:37 Run:1
Running from C:\Users\romana\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-10-28] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-10-28] (Samsung)
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\...\Run: [GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
SearchScopes: HKCU - URL http://search.conduit.com/Results.aspx? ... DCD44F4&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... hx?prefix={searchTerms}
R2 PanService; C:\Program Files\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
C:\Program Files\PANDORA.TV
2014-08-29 13:26 - 2014-08-29 13:26 - 00013230 _____ () C:\Users\romana\Desktop\FRST.txt
2014-08-29 11:27 - 2014-08-29 11:12 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-29 11:13 - 2014-08-29 12:12 - 00015236 _____ () C:\zoek-results.log
2014-08-29 11:12 - 2014-08-29 11:25 - 00000000 ____D () C:\zoek_backup
2014-08-29 11:12 - 2014-08-29 11:12 - 01288704 _____ () C:\Users\romana\Downloads\zoek.exe
2014-08-29 10:46 - 2014-08-29 10:46 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe
2014-08-29 10:34 - 2014-08-29 10:40 - 00000000 ____D () C:\AdwCleaner
2014-08-29 10:33 - 2014-08-29 10:33 - 01364531 _____ () C:\Users\romana\Downloads\adwcleaner_3.308.exe
2014-08-29 10:16 - 2014-08-29 10:16 - 00000000 ____D () C:\Windows\ERUNT
2014-08-29 10:15 - 2014-08-29 10:16 - 01016261 _____ (Thisisu) C:\Users\romana\Downloads\JRT.exe
2014-08-29 09:33 - 2014-08-29 09:34 - 00000000 ____D () C:\Program Files\trend micro
2014-08-29 09:33 - 2014-08-29 09:33 - 00000000 ____D () C:\rsit
2014-08-29 09:32 - 2014-08-29 09:32 - 00781909 _____ () C:\Users\romana\Downloads\RSIT.exe
Hosts:
Reboot:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KiesTrayAgent => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-11] (Microsoft Corporation) => Value not found.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\KiesPreload => value deleted successfully.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-1005143331-3529429533-888148122-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_D9E5435E96C40615E21675DF910A0D69 => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL http://search.conduit.com/Results.aspx? ... => Value not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON http://suggest.search.conduit.com/CSugg ... => Value not found.
PanService => Service stopped successfully.
PanService => Service deleted successfully.
C:\Program Files\PANDORA.TV => Moved successfully.
C:\Users\romana\Desktop\FRST.txt => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
"C:\Users\romana\Downloads\zoek.exe" => File/Directory not found.
"C:\Users\romana\Downloads\adwcleaner_3.308 (1).exe" => File/Directory not found.
C:\AdwCleaner => Moved successfully.
"C:\Users\romana\Downloads\adwcleaner_3.308.exe" => File/Directory not found.
C:\Windows\ERUNT => Moved successfully.
"C:\Users\romana\Downloads\JRT.exe" => File/Directory not found.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
"C:\Users\romana\Downloads\RSIT.exe" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====
Re: Hromada reklam všude a pořád
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Hromada reklam všude a pořád
Tedy to byla krasojízda! Moc Vám děkuju, zdá se, že vše šlape vzorně. Mám ještě jeden nesmělý dotaz: Často mi padá net a poskytovatel už vyloučil všechny možnosti z jeho strany - je možné, že je chyba někde v kompu? Díky za Váš čas 




Přispějete na provoz fóra?