istartsurf
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
istartsurf
Zdravím, kamarádka mi přinesla noťas, že má všude v prohlížečích IstartSurf...zkoušeli jsme změnit domovskou stránku a vyhledávač podle návodu na netu, ale je to tam pořád. Prosím o pomoc.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2014
Ran by Mel (administrator) on MEL-PC on 24-09-2014 10:41:34
Running from C:\Users\Mel\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\Rezip.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Speedchecker) C:\Program Files (x86)\Internet Speed Checker\a4126a03-d894-4d64-9db5-d4b8e28e5f49.exe
() C:\Program Files (x86)\Internet Speed Checker\371cbe38-1b95-4c54-adec-81f13f92edd5.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\avastui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(VER_COMPANY_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Speedchecker) C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2703752 2010-03-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-01] (AVAST Software)
HKLM-x32\...\Run: [VideoDownloadConverter EPM Support] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zmedint.exe [12872 2013-12-22] (Mindspark Interactive Network, Inc.)
HKLM-x32\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader 64] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe [71752 2013-12-22] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_15_0_0_152_ActiveX.exe [540336 2014-09-10] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (No File)
Startup: C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - DefaultScope {60658519-0D9A-4428-A557-06552EA4332C} URL = http://search.seznam.cz/?q={searchTerms ... arch_13906
SearchScopes: HKCU - {084374C8-FDA4-4D3E-864A-B0F8BCB57792} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13906
SearchScopes: HKCU - {1E29C3FF-5417-40E0-858A-D446E2CA26FA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {60658519-0D9A-4428-A557-06552EA4332C} URL = http://search.seznam.cz/?q={searchTerms ... arch_13906
SearchScopes: HKCU - {8E9CAF1C-3613-4352-8C81-74F3400FE651} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13906
SearchScopes: HKCU - {9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {B64F33CD-1636-48F1-922D-87C14747AE4B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906
SearchScopes: HKCU - {C3D720EC-9215-4F88-91D2-D0EA71379EB8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13906
SearchScopes: HKCU - {CB72987E-FC28-4A7A-A397-158251779E83} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13906
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - {D89ACF06-CF05-4B31-81A8-F6F05D028724} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13906
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C932B377-4F63-4734-88E7-F9A326CF1CE6}: [NameServer] 80.78.144.6,80.78.144.7
FireFox:
========
FF ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
FF SearchEngineOrder.1: Seznam
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (Mindspark)
FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin -> C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll (Mindspark)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\user.js
FF SearchPlugin: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Internet Speed Checker - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\sepherdwilbur@aol.com [2014-09-21]
FF Extension: Seznam lištička - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-07-10]
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-07-02]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\extensions\faststartff@gmail.com
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
Chrome:
=======
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Bing Bar) - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
CHR Profile: C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Email) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-01-08]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-01-08]
CHR Extension: (YouTube) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-16]
CHR Extension: (Google Search) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-16]
CHR Extension: (Google Wallet) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-01-08]
CHR Extension: (Gmail) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-09-19] (Cherished Technololgy LIMITED)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Rezip; C:\Windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
R2 VideoDownloadConverter_4zService; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [88648 2013-12-22] (COMPANYVERS_NAME)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-14] (Symantec Corporation)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-10-15] (Windows (R) 2003 DDK 3790 provider)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
R1 {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64; C:\Windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys [44728 2014-09-19] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 10:41 - 2014-09-24 10:42 - 00029085 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 10:39 - 2014-09-24 10:40 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-20 12:39 - 2014-09-24 10:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00004494 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00003812 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002786 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002108 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00001482 _____ () C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00000648 _____ () C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job
2014-09-20 12:39 - 2014-09-20 12:39 - 00007524 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
2014-09-20 12:39 - 2014-09-20 12:39 - 00006842 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
2014-09-20 12:39 - 2014-09-20 12:39 - 00006498 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
2014-09-20 12:39 - 2014-09-20 12:39 - 00006496 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
2014-09-20 12:39 - 2014-09-20 12:39 - 00005816 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
2014-09-20 12:39 - 2014-09-20 12:39 - 00005474 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
2014-09-20 12:39 - 2014-09-20 12:39 - 00005138 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
2014-09-20 12:39 - 2014-09-20 12:39 - 00004512 _____ () C:\Windows\System32\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49
2014-09-20 12:39 - 2014-09-20 12:39 - 00003666 _____ () C:\Windows\System32\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Users\Mel\AppData\Local\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-20 12:38 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\Internet Speed Checker
2014-09-20 12:19 - 2014-09-20 12:19 - 00000000 ____D () C:\Users\Mel\.android
2014-09-20 12:18 - 2014-09-22 20:03 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-20 12:18 - 2014-09-20 12:18 - 00000000 ____D () C:\Users\Mel\AppData\Local\CrashRpt
2014-09-20 12:17 - 2014-09-23 09:06 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-20 12:17 - 2014-09-22 20:03 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00001028 _____ () C:\Users\Mel\Desktop\Driver Pro.lnk
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Program Files (x86)\Driver Pro
2014-09-19 21:27 - 2014-09-19 00:48 - 00044728 _____ (StdLib) C:\Windows\system32\Drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
2014-09-19 21:26 - 2014-09-20 13:07 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-09-19 21:25 - 2014-09-20 13:09 - 00000000 ____D () C:\Program Files (x86)\Ttessab
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\istartsurf
2014-09-19 21:23 - 2014-09-20 12:20 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 10:42 - 2014-09-24 10:41 - 00029085 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 10:40 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 10:40 - 2012-03-26 21:05 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:39 - 2014-09-20 12:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-24 10:28 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-24 10:28 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-24 10:13 - 2013-08-06 07:34 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-24 10:12 - 2010-08-09 21:20 - 02003812 _____ () C:\Windows\WindowsUpdate.log
2014-09-24 10:10 - 2011-07-08 18:03 - 00000000 ____D () C:\Users\Mel\Documents\záloha registrů ccleaner
2014-09-24 09:16 - 2012-07-11 10:37 - 00004184 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-24 09:15 - 2014-09-20 12:39 - 00004494 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00003812 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002786 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002108 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00001482 _____ () C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00000648 _____ () C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job
2014-09-24 09:15 - 2013-04-08 11:49 - 00000920 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job
2014-09-23 11:54 - 2013-04-08 11:49 - 00000898 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job
2014-09-23 11:40 - 2012-03-26 21:05 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-23 09:22 - 2010-08-09 21:43 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-23 09:22 - 2010-08-09 21:43 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-23 09:22 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-23 09:06 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-23 09:02 - 2011-01-28 18:06 - 00000000 ____D () C:\Users\Mel\Tracing
2014-09-22 20:03 - 2014-09-20 12:18 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-22 20:03 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Driver Pro
2014-09-21 11:10 - 2012-09-16 09:07 - 00002241 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-21 10:34 - 2014-09-21 10:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-20 13:16 - 2014-01-08 12:00 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Seznam.cz
2014-09-20 13:10 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-20 13:09 - 2014-09-19 21:25 - 00000000 ____D () C:\Program Files (x86)\Ttessab
2014-09-20 13:07 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-09-20 12:52 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-09-20 12:41 - 2010-08-09 06:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-20 12:39 - 2014-09-20 12:39 - 00007524 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
2014-09-20 12:39 - 2014-09-20 12:39 - 00006842 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
2014-09-20 12:39 - 2014-09-20 12:39 - 00006498 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
2014-09-20 12:39 - 2014-09-20 12:39 - 00006496 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
2014-09-20 12:39 - 2014-09-20 12:39 - 00005816 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
2014-09-20 12:39 - 2014-09-20 12:39 - 00005474 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
2014-09-20 12:39 - 2014-09-20 12:39 - 00005138 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
2014-09-20 12:39 - 2014-09-20 12:39 - 00004512 _____ () C:\Windows\System32\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49
2014-09-20 12:39 - 2014-09-20 12:39 - 00003666 _____ () C:\Windows\System32\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Users\Mel\AppData\Local\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:38 - 00000000 ____D () C:\Program Files (x86)\Internet Speed Checker
2014-09-20 12:20 - 2014-09-19 21:23 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
2014-09-20 12:19 - 2014-09-20 12:19 - 00000000 ____D () C:\Users\Mel\.android
2014-09-20 12:19 - 2010-11-09 21:22 - 00000000 ____D () C:\Users\Mel
2014-09-20 12:18 - 2014-09-20 12:18 - 00000000 ____D () C:\Users\Mel\AppData\Local\CrashRpt
2014-09-20 12:17 - 2014-09-20 12:17 - 00001028 _____ () C:\Users\Mel\Desktop\Driver Pro.lnk
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Program Files (x86)\Driver Pro
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-20 12:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\istartsurf
2014-09-19 21:25 - 2014-03-23 17:25 - 00002471 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-19 21:25 - 2012-03-02 08:30 - 00001593 _____ () C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-19 21:25 - 2010-11-09 21:53 - 00001601 _____ () C:\Users\Mel\Desktop\Internet Explorer.lnk
2014-09-19 21:24 - 2010-08-09 06:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-19 00:48 - 2014-09-19 21:27 - 00044728 _____ (StdLib) C:\Windows\system32\Drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
2014-09-17 19:27 - 2010-11-09 21:54 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Skype
2014-09-15 17:14 - 2012-12-15 16:48 - 00000472 ____H () C:\Windows\Tasks\Norton Security Scan for Mel.job
2014-09-11 10:16 - 2010-12-12 12:44 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\skypePM
2014-09-10 19:03 - 2013-08-06 07:34 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 19:03 - 2013-08-06 07:34 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 19:03 - 2012-01-26 17:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-25 06:53 - 2010-12-16 20:43 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job => C:\Program Files (x86)\Internet Speed Checker\371cbe38-1b95-4c54-adec-81f13f92edd5.exe
Task: C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job => C:\Program Files (x86)\Internet Speed Checker\a4126a03-d894-4d64-9db5-d4b8e28e5f49.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job => C:\Program Files (x86)\Internet Speed Checker\Internet Speed Checker-codedownloader.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mel\Desktop" je 523 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2014
Ran by Mel (administrator) on MEL-PC on 24-09-2014 10:41:34
Running from C:\Users\Mel\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\Rezip.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Speedchecker) C:\Program Files (x86)\Internet Speed Checker\a4126a03-d894-4d64-9db5-d4b8e28e5f49.exe
() C:\Program Files (x86)\Internet Speed Checker\371cbe38-1b95-4c54-adec-81f13f92edd5.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\avastui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(VER_COMPANY_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Speedchecker) C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2703752 2010-03-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-01] (AVAST Software)
HKLM-x32\...\Run: [VideoDownloadConverter EPM Support] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zmedint.exe [12872 2013-12-22] (Mindspark Interactive Network, Inc.)
HKLM-x32\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader 64] => C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon64.exe [71752 2013-12-22] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil64_15_0_0_152_ActiveX.exe [540336 2014-09-10] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (No File)
Startup: C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... J9AZ941420
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - DefaultScope {60658519-0D9A-4428-A557-06552EA4332C} URL = http://search.seznam.cz/?q={searchTerms ... arch_13906
SearchScopes: HKCU - {084374C8-FDA4-4D3E-864A-B0F8BCB57792} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13906
SearchScopes: HKCU - {1E29C3FF-5417-40E0-858A-D446E2CA26FA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - {60658519-0D9A-4428-A557-06552EA4332C} URL = http://search.seznam.cz/?q={searchTerms ... arch_13906
SearchScopes: HKCU - {8E9CAF1C-3613-4352-8C81-74F3400FE651} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13906
SearchScopes: HKCU - {9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {B64F33CD-1636-48F1-922D-87C14747AE4B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906
SearchScopes: HKCU - {C3D720EC-9215-4F88-91D2-D0EA71379EB8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13906
SearchScopes: HKCU - {CB72987E-FC28-4A7A-A397-158251779E83} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13906
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain. ... earchTerms}
SearchScopes: HKCU - {D89ACF06-CF05-4B31-81A8-F6F05D028724} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13906
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C932B377-4F63-4734-88E7-F9A326CF1CE6}: [NameServer] 80.78.144.6,80.78.144.7
FireFox:
========
FF ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
FF SearchEngineOrder.1: Seznam
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @VideoDownloadConverter_4z.com/Plugin -> C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (Mindspark)
FF Plugin-x32: @VideoDownloadConverter_ScriptHelper.com/Plugin -> C:\Program Files (x86)\VideoDownloadConverter\npVDCPlugin.dll (Mindspark)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\user.js
FF SearchPlugin: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\istartsurf.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Internet Speed Checker - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\sepherdwilbur@aol.com [2014-09-21]
FF Extension: Seznam lištička - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-07-10]
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-07-02]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\extensions\faststartff@gmail.com
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
Chrome:
=======
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Bing Bar) - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
CHR Profile: C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Seznam Lištička - Email) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-01-08]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-01-08]
CHR Extension: (YouTube) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-16]
CHR Extension: (Google Search) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-16]
CHR Extension: (Google Wallet) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-01-08]
CHR Extension: (Gmail) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.istartsurf.com/?type=sc&ts=1 ... J9AZ941420
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-09-19] (Cherished Technololgy LIMITED)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Rezip; C:\Windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
R2 VideoDownloadConverter_4zService; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [88648 2013-12-22] (COMPANYVERS_NAME)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-14] (Symantec Corporation)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-10-15] (Windows (R) 2003 DDK 3790 provider)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
R1 {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64; C:\Windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys [44728 2014-09-19] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 10:41 - 2014-09-24 10:42 - 00029085 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 10:39 - 2014-09-24 10:40 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-20 12:39 - 2014-09-24 10:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00004494 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00003812 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002786 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00002108 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00001482 _____ () C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job
2014-09-20 12:39 - 2014-09-24 09:15 - 00000648 _____ () C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job
2014-09-20 12:39 - 2014-09-20 12:39 - 00007524 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
2014-09-20 12:39 - 2014-09-20 12:39 - 00006842 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
2014-09-20 12:39 - 2014-09-20 12:39 - 00006498 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
2014-09-20 12:39 - 2014-09-20 12:39 - 00006496 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
2014-09-20 12:39 - 2014-09-20 12:39 - 00005816 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
2014-09-20 12:39 - 2014-09-20 12:39 - 00005474 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
2014-09-20 12:39 - 2014-09-20 12:39 - 00005138 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
2014-09-20 12:39 - 2014-09-20 12:39 - 00004512 _____ () C:\Windows\System32\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49
2014-09-20 12:39 - 2014-09-20 12:39 - 00003666 _____ () C:\Windows\System32\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Users\Mel\AppData\Local\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-20 12:38 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\Internet Speed Checker
2014-09-20 12:19 - 2014-09-20 12:19 - 00000000 ____D () C:\Users\Mel\.android
2014-09-20 12:18 - 2014-09-22 20:03 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-20 12:18 - 2014-09-20 12:18 - 00000000 ____D () C:\Users\Mel\AppData\Local\CrashRpt
2014-09-20 12:17 - 2014-09-23 09:06 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-20 12:17 - 2014-09-22 20:03 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00001028 _____ () C:\Users\Mel\Desktop\Driver Pro.lnk
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Program Files (x86)\Driver Pro
2014-09-19 21:27 - 2014-09-19 00:48 - 00044728 _____ (StdLib) C:\Windows\system32\Drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
2014-09-19 21:26 - 2014-09-20 13:07 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-09-19 21:25 - 2014-09-20 13:09 - 00000000 ____D () C:\Program Files (x86)\Ttessab
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\istartsurf
2014-09-19 21:23 - 2014-09-20 12:20 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 10:42 - 2014-09-24 10:41 - 00029085 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 10:40 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 10:40 - 2012-03-26 21:05 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:39 - 2014-09-20 12:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-24 10:28 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-24 10:28 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-24 10:13 - 2013-08-06 07:34 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-24 10:12 - 2010-08-09 21:20 - 02003812 _____ () C:\Windows\WindowsUpdate.log
2014-09-24 10:10 - 2011-07-08 18:03 - 00000000 ____D () C:\Users\Mel\Documents\záloha registrů ccleaner
2014-09-24 09:16 - 2012-07-11 10:37 - 00004184 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-24 09:15 - 2014-09-20 12:39 - 00004494 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00003812 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00003468 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002786 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002444 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00002108 _____ () C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00001482 _____ () C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job
2014-09-24 09:15 - 2014-09-20 12:39 - 00000648 _____ () C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job
2014-09-24 09:15 - 2013-04-08 11:49 - 00000920 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job
2014-09-23 11:54 - 2013-04-08 11:49 - 00000898 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job
2014-09-23 11:40 - 2012-03-26 21:05 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-23 09:22 - 2010-08-09 21:43 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-23 09:22 - 2010-08-09 21:43 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-23 09:22 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-23 09:06 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-23 09:02 - 2011-01-28 18:06 - 00000000 ____D () C:\Users\Mel\Tracing
2014-09-22 20:03 - 2014-09-20 12:18 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-22 20:03 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Driver Pro
2014-09-21 11:10 - 2012-09-16 09:07 - 00002241 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-21 10:34 - 2014-09-21 10:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-20 13:16 - 2014-01-08 12:00 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Seznam.cz
2014-09-20 13:10 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-20 13:09 - 2014-09-19 21:25 - 00000000 ____D () C:\Program Files (x86)\Ttessab
2014-09-20 13:07 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-09-20 12:52 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-09-20 12:41 - 2010-08-09 06:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-20 12:39 - 2014-09-20 12:39 - 00007524 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
2014-09-20 12:39 - 2014-09-20 12:39 - 00006842 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
2014-09-20 12:39 - 2014-09-20 12:39 - 00006498 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
2014-09-20 12:39 - 2014-09-20 12:39 - 00006496 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
2014-09-20 12:39 - 2014-09-20 12:39 - 00005816 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
2014-09-20 12:39 - 2014-09-20 12:39 - 00005474 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
2014-09-20 12:39 - 2014-09-20 12:39 - 00005138 _____ () C:\Windows\System32\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
2014-09-20 12:39 - 2014-09-20 12:39 - 00004512 _____ () C:\Windows\System32\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49
2014-09-20 12:39 - 2014-09-20 12:39 - 00003666 _____ () C:\Windows\System32\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Users\Mel\AppData\Local\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:39 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-20 12:39 - 2014-09-20 12:38 - 00000000 ____D () C:\Program Files (x86)\Internet Speed Checker
2014-09-20 12:20 - 2014-09-19 21:23 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
2014-09-20 12:19 - 2014-09-20 12:19 - 00000000 ____D () C:\Users\Mel\.android
2014-09-20 12:19 - 2010-11-09 21:22 - 00000000 ____D () C:\Users\Mel
2014-09-20 12:18 - 2014-09-20 12:18 - 00000000 ____D () C:\Users\Mel\AppData\Local\CrashRpt
2014-09-20 12:17 - 2014-09-20 12:17 - 00001028 _____ () C:\Users\Mel\Desktop\Driver Pro.lnk
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Program Files (x86)\Driver Pro
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-20 12:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-09-19 21:26 - 2014-09-19 21:26 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\istartsurf
2014-09-19 21:25 - 2014-03-23 17:25 - 00002471 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-19 21:25 - 2012-03-02 08:30 - 00001593 _____ () C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-19 21:25 - 2010-11-09 21:53 - 00001601 _____ () C:\Users\Mel\Desktop\Internet Explorer.lnk
2014-09-19 21:24 - 2010-08-09 06:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-19 00:48 - 2014-09-19 21:27 - 00044728 _____ (StdLib) C:\Windows\system32\Drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
2014-09-17 19:27 - 2010-11-09 21:54 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Skype
2014-09-15 17:14 - 2012-12-15 16:48 - 00000472 ____H () C:\Windows\Tasks\Norton Security Scan for Mel.job
2014-09-11 10:16 - 2010-12-12 12:44 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\skypePM
2014-09-10 19:03 - 2013-08-06 07:34 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 19:03 - 2013-08-06 07:34 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 19:03 - 2012-01-26 17:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-25 06:53 - 2010-12-16 20:43 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\371cbe38-1b95-4c54-adec-81f13f92edd5.job => C:\Program Files (x86)\Internet Speed Checker\371cbe38-1b95-4c54-adec-81f13f92edd5.exe
Task: C:\Windows\Tasks\a4126a03-d894-4d64-9db5-d4b8e28e5f49.job => C:\Program Files (x86)\Internet Speed Checker\a4126a03-d894-4d64-9db5-d4b8e28e5f49.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-1.job => C:\Program Files (x86)\Internet Speed Checker\Internet Speed Checker-codedownloader.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-11.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-2.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-4.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-5.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-6.exe
Task: C:\Windows\Tasks\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.job => C:\Program Files (x86)\Internet Speed Checker\ad6a7a06-e2c9-47d9-a9a2-63094643e086-7.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mel\Desktop" je 523 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: istartsurf
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: istartsurf
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.0 (09.22.2014:1)
OS: Windows 7 Home Premium x64
Ran by Mel on st 24.09.2014 at 12:44:40,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update ttessab
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622172252}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622172252}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{60658519-0D9A-4428-A557-06552EA4332C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
~~~ Files
Successfully deleted: [File] "C:\Users\Mel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Mel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Mel\AppData\Roaming\driver pro"
Successfully deleted: [Folder] "C:\Users\Mel\AppData\Roaming\registry mechanic"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\local\iac"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\local\videodownloadconverter_4z"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\locallow\iac"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\locallow\videodownloadconverter_4z"
Successfully deleted: [Folder] "C:\Program Files (x86)\driver pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\ttessab"
Failed to delete: [Folder] "C:\Program Files (x86)\videodownloadconverter_4z"
~~~ FireFox
Successfully deleted: [File] C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\user.js
Successfully deleted: [Folder] C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\extensions\staged
Successfully deleted the following from C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\prefs.js
user_pref("browser.search.defaulturl", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750126.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAAP8AAAD/CAYAAAA+CADK
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750127.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbM
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750128.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAYAAABXAvmH
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22
user_pref("extensions.asepherdwilburaolcom61752.61752.thankyou", "hxxp://crossrider.com/thank_you/61752");
user_pref("extensions.crossrider.bic", "14892b41e10701308292119f3e79a8b2");
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 24.09.2014 at 12:49:38,34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.0 (09.22.2014:1)
OS: Windows 7 Home Premium x64
Ran by Mel on st 24.09.2014 at 12:44:40,07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update ttessab
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.FeedManager.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLMenu.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.HTMLPanel.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.MultipleButton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.PseudoTransparentPlugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.Radio.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.RadioSettings.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ScriptButton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.SettingsPlugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ThirdPartyInstaller.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\VideoDownloadConverter_4z.ToolbarProtector.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622172252}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622172252}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655175552}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666176652}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644174452}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilTtessab_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilTtessab_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{60658519-0D9A-4428-A557-06552EA4332C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
~~~ Files
Successfully deleted: [File] "C:\Users\Mel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Mel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Mel\AppData\Roaming\driver pro"
Successfully deleted: [Folder] "C:\Users\Mel\AppData\Roaming\registry mechanic"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\local\iac"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\local\videodownloadconverter_4z"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\locallow\iac"
Successfully deleted: [Folder] "C:\Users\Mel\appdata\locallow\videodownloadconverter_4z"
Successfully deleted: [Folder] "C:\Program Files (x86)\driver pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\ttessab"
Failed to delete: [Folder] "C:\Program Files (x86)\videodownloadconverter_4z"
~~~ FireFox
Successfully deleted: [File] C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\user.js
Successfully deleted: [Folder] C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\extensions\staged
Successfully deleted the following from C:\Users\Mel\AppData\Roaming\mozilla\firefox\profiles\gtm80pq3.default\prefs.js
user_pref("browser.search.defaulturl", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750126.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAAP8AAAD/CAYAAAA+CADK
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750127.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAABMAAAATCAYAAAByUDbM
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750128.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEUgAAADAAAAAwCAYAAABXAvmH
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22
user_pref("extensions.asepherdwilburaolcom61752.61752.thankyou", "hxxp://crossrider.com/thank_you/61752");
user_pref("extensions.crossrider.bic", "14892b41e10701308292119f3e79a8b2");
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 24.09.2014 at 12:49:38,34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: istartsurf
# AdwCleaner v3.310 - Report created 24/09/2014 at 14:37:10
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Mel - MEL-PC
# Running from : C:\Users\Mel\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : IePluginServices
[#] Service Deleted : VideoDownloadConverter_4zService
Service Deleted : {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter
Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter_4z
Folder Deleted : C:\Program Files (x86)\Internet Speed Checker
Folder Deleted : C:\Users\Mel\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Mel\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\Mel\AppData\LocalLow\Internet Speed Checker
Folder Deleted : C:\Users\Mel\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\sepherdwilbur@aol.com
File Deleted : C:\Windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
File Deleted : C:\Users\Mel\Desktop\Driver Pro.lnk
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
***** [ Scheduled Tasks ] *****
Task Deleted : 371cbe38-1b95-4c54-adec-81f13f92edd5
Task Deleted : a4126a03-d894-4d64-9db5-d4b8e28e5f49
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Mel\Desktop\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter.ScriptHelper
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter EPM Support]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter_4z Browser Plugin Loader 64]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A1260C1-2964-453F-B0BA-FA429472EB5F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{363D5C92-10DC-4287-93E5-1832EECC48EC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3719959C-1CCD-4FA7-8EBB-7D9DED86FCCB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B41BE90-F731-4137-AFF3-2CA951E7F0D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4128C64D-F0DD-4811-9405-D22294E8151F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69407823-3494-4400-8D49-612549E8F4EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{84B7B98F-E018-4DBB-AB4C-4DDD3DFCB5FB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8FCA5302-6D6D-4645-BF99-D43CF76CE474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD385519-22E7-4BE2-8A8D-35C66DF4858E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FF48DBA6-5DD8-4D10-9EB0-0FA968502E66}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{37923200-6887-4B44-95D4-CAE8F83ECFEE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{385F1935-3784-48D0-A61F-6385493DED3C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
Key Deleted : HKCU\Software\Driver Pro
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\VideoDownloadConverter_4z
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter_4zbar Uninstall Firefox
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (cs)
[ File : C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js ]
Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", true);
-\\ Google Chrome v37.0.2062.120
[ File : C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1411 ... earchTerms}
*************************
AdwCleaner[R0].txt - [17486 octets] - [24/09/2014 12:51:18]
AdwCleaner[R1].txt - [17547 octets] - [24/09/2014 14:36:26]
AdwCleaner[S0].txt - [15145 octets] - [24/09/2014 14:37:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15206 octets] ##########
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Mel - MEL-PC
# Running from : C:\Users\Mel\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : IePluginServices
[#] Service Deleted : VideoDownloadConverter_4zService
Service Deleted : {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter
Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter_4z
Folder Deleted : C:\Program Files (x86)\Internet Speed Checker
Folder Deleted : C:\Users\Mel\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Mel\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\Mel\AppData\LocalLow\Internet Speed Checker
Folder Deleted : C:\Users\Mel\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
Folder Deleted : C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\sepherdwilbur@aol.com
File Deleted : C:\Windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
File Deleted : C:\Users\Mel\Desktop\Driver Pro.lnk
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
***** [ Scheduled Tasks ] *****
Task Deleted : 371cbe38-1b95-4c54-adec-81f13f92edd5
Task Deleted : a4126a03-d894-4d64-9db5-d4b8e28e5f49
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-1
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-11
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-2
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-4
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-5
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-5_user
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-6
Task Deleted : ad6a7a06-e2c9-47d9-a9a2-63094643e086-7
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Mel\Desktop\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Mel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\VideoDownloadConverter.ScriptHelper
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter EPM Support]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VideoDownloadConverter_4z Browser Plugin Loader 64]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A1260C1-2964-453F-B0BA-FA429472EB5F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{363D5C92-10DC-4287-93E5-1832EECC48EC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3719959C-1CCD-4FA7-8EBB-7D9DED86FCCB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B41BE90-F731-4137-AFF3-2CA951E7F0D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4128C64D-F0DD-4811-9405-D22294E8151F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69407823-3494-4400-8D49-612549E8F4EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{84B7B98F-E018-4DBB-AB4C-4DDD3DFCB5FB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8FCA5302-6D6D-4645-BF99-D43CF76CE474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD385519-22E7-4BE2-8A8D-35C66DF4858E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FF48DBA6-5DD8-4D10-9EB0-0FA968502E66}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{192F487E-E812-40C0-B0DE-CB4BFA20F37B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D3826A1-F3E8-45D6-94B5-C26D8EC0073B}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{37923200-6887-4B44-95D4-CAE8F83ECFEE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{385F1935-3784-48D0-A61F-6385493DED3C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3EE17DD1-E28B-4AED-A3B2-9C29CB2C19D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{79332472-47F3-4E32-B07F-CF8DF4C58499}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{886F93AD-3CBB-4424-8442-A7340243540F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AA289DBC-59B6-40A5-AC7D-C90DF850289C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BC153A3C-0BB7-4EED-83AE-28E6E398F56E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CA723163-6FAD-43D4-8B93-0D8C52BD9974}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F1F328EB-F5A5-432B-A54C-05F3EF5B0BD8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FE8DBB09-C3D3-4477-80CB-D38914B94BB8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1F6F39C1-00A8-4752-A94C-D0EA92D978B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5354D921-3F52-47C5-938D-77A2FB6DEFE7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71144427-1368-4D18-8DC9-2AE3CC4C4F83}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A86782D8-7B41-452F-A217-1854F72DBA54}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED345812-2722-4DCA-9976-D01832DB44EE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D429207-4689-492D-A0E5-CDC5DFBB5005}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
Key Deleted : HKCU\Software\Driver Pro
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\VideoDownloadConverter_4z
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\VideoDownloadConverter_4z
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter
Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4z
Key Deleted : HKLM\SOFTWARE\Internet Speed Checker
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoDownloadConverter_4zbar Uninstall Firefox
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (cs)
[ File : C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js ]
Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", true);
-\\ Google Chrome v37.0.2062.120
[ File : C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1411 ... earchTerms}
*************************
AdwCleaner[R0].txt - [17486 octets] - [24/09/2014 12:51:18]
AdwCleaner[R1].txt - [17547 octets] - [24/09/2014 14:36:26]
AdwCleaner[S0].txt - [15145 octets] - [24/09/2014 14:37:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15206 octets] ##########
Re: istartsurf
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: istartsurf
Zoek.exe v5.0.0.0 Updated 23-09-2014
Tool run by Mel on st 24.09.2014 at 15:17:21,41.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Mel\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
24.9.2014 15:18:13 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js:
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
Added to C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
user.js not found
---- Lines Search modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"msntoolbar@msn.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\
---- Lines asepherdwilburaolcom61752 removed from prefs.js ----
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"private
user_pref("extensions.asepherdwilburaolcom61752.61752.active", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.addressbar", "NA");
user_pref("extensions.asepherdwilburaolcom61752.61752.addressbarenhanced", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.asyncdb.was_copied", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.asyncinternaldb.was_copied", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.backgroundver", 1);
user_pref("extensions.asepherdwilburaolcom61752.61752.certdomaininstaller", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallationTime.value", "%221411209534%22");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220%22%2C%22
user_pref("extensions.asepherdwilburaolcom61752.61752.description", "Test your internet speed with 1-click");
user_pref("extensions.asepherdwilburaolcom61752.61752.domain", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.enablesearch", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.homepage", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.changeprevious", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.iframe", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.InstallationThankYouPage", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.InstallationTime", 1411209534);
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.__defualt_browser__.value", "%22ie%22");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B2%2C-2147483643%2C1048576%5D%2C
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%229234D4
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%229234D4835FE04951882B75ECBD2
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220%22%2
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%229234D4835FE0495188
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledWithHash.value", "null");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_last_executable_request.expiration", "Wed Sep 24 2014 22:39:57 GM
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_last_executable_request.value", "%22http%3A//vyosek.tym.cz/pro_us
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 2030 00:00:00 GMT
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_appVer.value", "55");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_nextCheck.expiration", "Wed Sep 24 2014 16:02:56 GMT+0200");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750126.expiration", "Fri Dec 19 2014 11:55:55 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750127.expiration", "Tue Dec 23 2014 09:39:52 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750128.expiration", "Fri Dec 19 2014 11:55:55 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.lastDailyReport", "1411545774873");
user_pref("extensions.asepherdwilburaolcom61752.61752.lastUpdate", "1411545776554");
user_pref("extensions.asepherdwilburaolcom61752.61752.manifesturl", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.name", "Internet Speed Checker1.1");
user_pref("extensions.asepherdwilburaolcom61752.61752.newtab", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.opensearch", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.pluginsurl", "http://js.newclientstaticsrv.com/plugin ... ugins.json");
user_pref("extensions.asepherdwilburaolcom61752.61752.pluginsversion", 50);
user_pref("extensions.asepherdwilburaolcom61752.61752.publisher", "Speedchecker");
user_pref("extensions.asepherdwilburaolcom61752.61752.searchstatus", 0);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasepherdwilburaolcom61752_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasepherdwilburaolcom61752_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncdb_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncinternaldb_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.setnewtab", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.updateinterval", 360);
user_pref("extensions.asepherdwilburaolcom61752.61752.ver", 55);
user_pref("extensions.asepherdwilburaolcom61752.apps", "61752");
user_pref("extensions.asepherdwilburaolcom61752.bic", "14892b41e10701308292119f3e79a8b2");
user_pref("extensions.asepherdwilburaolcom61752.cid", 61752);
user_pref("extensions.asepherdwilburaolcom61752.firstrun", false);
user_pref("extensions.asepherdwilburaolcom61752.hadappinstalled", true);
user_pref("extensions.asepherdwilburaolcom61752.installationdate", 1411210551);
user_pref("extensions.asepherdwilburaolcom61752.installerAdditionalInfo", "{\"asw\":[2, -2147483643, 1048576],\"browser_name\":\"ff\"}");
user_pref("extensions.asepherdwilburaolcom61752.modetype", "production");
user_pref("extensions.asepherdwilburaolcom61752.reportInstall", true);
user_pref("extensions.asepherdwilburaolcom61752.statsDailyCounter", 2);
---- FireFox user.js and prefs.js backups ----
prefs_24.09.2014_1528_.backup
==== Deleting Files \ Folders ======================
C:\Users\Mel\.android deleted
C:\PROGRA~2\GUT1655.tmp deleted
C:\PROGRA~2\GUTBBDB.tmp deleted
C:\PROGRA~2\GUM1654.tmp deleted
C:\PROGRA~2\GUMBBDA.tmp deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~3\OberonGameConsole deleted
C:\Users\Mel\AppData\Local\CrashRpt deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [14.07.2014 22:56]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04.04.2014 12:36]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
F6D12679B9112358AC705A1308156F59 - C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director
DAD55CEF682EAE6FA7B4C9487563A496 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll - Shockwave for Director / Shockwave for Director
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[14.07.2014 22:56]
Seznam Li\u0161ti\u010Dka - Email - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Seznam Lištička - Rychlá volba - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
==== Chromium Fix ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{084374C8-FDA4-4D3E-864A-B0F8BCB57792} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13906"
{1E29C3FF-5417-40E0-858A-D446E2CA26FA} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13906"
{8E9CAF1C-3613-4352-8C81-74F3400FE651} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_13906"
{9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13906"
{B64F33CD-1636-48F1-922D-87C14747AE4B} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906"
{C1916D8B-B4C8-4901-98B1-D60A87C0A846} Bing Url="http://www.bing.com/search?FORM=SMSTDF& ... -SearchBox"
{C3D720EC-9215-4F88-91D2-D0EA71379EB8} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_13906"
{CB72987E-FC28-4A7A-A397-158251779E83} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_13906"
{D89ACF06-CF05-4B31-81A8-F6F05D028724} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_13906"
==== Reset Google Chrome ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Mel\AppData\Local\Mozilla\Firefox\Profiles\gtm80pq3.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1331 folders=128 57051414 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Mel\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Mel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 24.09.2014 at 15:38:35,57 ======================
Tool run by Mel on st 24.09.2014 at 15:17:21,41.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Mel\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
24.9.2014 15:18:13 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js:
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
Added to C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
user.js not found
---- Lines Search modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"msntoolbar@msn.com\":{\"descriptor\":\"C:\\\\Program Files (x86)\
---- Lines asepherdwilburaolcom61752 removed from prefs.js ----
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"private
user_pref("extensions.asepherdwilburaolcom61752.61752.active", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.addressbar", "NA");
user_pref("extensions.asepherdwilburaolcom61752.61752.addressbarenhanced", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.asyncdb.was_copied", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.asyncinternaldb.was_copied", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.backgroundver", 1);
user_pref("extensions.asepherdwilburaolcom61752.61752.certdomaininstaller", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallationTime.value", "%221411209534%22");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220%22%2C%22
user_pref("extensions.asepherdwilburaolcom61752.61752.description", "Test your internet speed with 1-click");
user_pref("extensions.asepherdwilburaolcom61752.61752.domain", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.enablesearch", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.homepage", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.changeprevious", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.iframe", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.InstallationThankYouPage", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.InstallationTime", 1411209534);
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.__defualt_browser__.value", "%22ie%22");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B2%2C-2147483643%2C1048576%5D%2C
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%229234D4
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%229234D4835FE04951882B75ECBD2
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220%22%2
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22001726%22%2C%22sub_id%22%3A%220
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%229234D4835FE0495188
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledWithHash.value", "null");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_last_executable_request.expiration", "Wed Sep 24 2014 22:39:57 GM
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_last_executable_request.value", "%22http%3A//vyosek.tym.cz/pro_us
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 2030 00:00:00 GMT
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_appVer.value", "55");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_nextCheck.expiration", "Wed Sep 24 2014 16:02:56 GMT+0200");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750126.expiration", "Fri Dec 19 2014 11:55:55 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750127.expiration", "Tue Dec 23 2014 09:39:52 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_resource_750128.expiration", "Fri Dec 19 2014 11:55:55 GMT+0100");
user_pref("extensions.asepherdwilburaolcom61752.61752.lastDailyReport", "1411545774873");
user_pref("extensions.asepherdwilburaolcom61752.61752.lastUpdate", "1411545776554");
user_pref("extensions.asepherdwilburaolcom61752.61752.manifesturl", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.name", "Internet Speed Checker1.1");
user_pref("extensions.asepherdwilburaolcom61752.61752.newtab", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.opensearch", "");
user_pref("extensions.asepherdwilburaolcom61752.61752.pluginsurl", "http://js.newclientstaticsrv.com/plugin ... ugins.json");
user_pref("extensions.asepherdwilburaolcom61752.61752.pluginsversion", 50);
user_pref("extensions.asepherdwilburaolcom61752.61752.publisher", "Speedchecker");
user_pref("extensions.asepherdwilburaolcom61752.61752.searchstatus", 0);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasepherdwilburaolcom61752_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasepherdwilburaolcom61752_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncdb_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncinternaldb_dbWasSet", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.sepherdwilbur@aol.comasyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.asepherdwilburaolcom61752.61752.setnewtab", false);
user_pref("extensions.asepherdwilburaolcom61752.61752.updateinterval", 360);
user_pref("extensions.asepherdwilburaolcom61752.61752.ver", 55);
user_pref("extensions.asepherdwilburaolcom61752.apps", "61752");
user_pref("extensions.asepherdwilburaolcom61752.bic", "14892b41e10701308292119f3e79a8b2");
user_pref("extensions.asepherdwilburaolcom61752.cid", 61752);
user_pref("extensions.asepherdwilburaolcom61752.firstrun", false);
user_pref("extensions.asepherdwilburaolcom61752.hadappinstalled", true);
user_pref("extensions.asepherdwilburaolcom61752.installationdate", 1411210551);
user_pref("extensions.asepherdwilburaolcom61752.installerAdditionalInfo", "{\"asw\":[2, -2147483643, 1048576],\"browser_name\":\"ff\"}");
user_pref("extensions.asepherdwilburaolcom61752.modetype", "production");
user_pref("extensions.asepherdwilburaolcom61752.reportInstall", true);
user_pref("extensions.asepherdwilburaolcom61752.statsDailyCounter", 2);
---- FireFox user.js and prefs.js backups ----
prefs_24.09.2014_1528_.backup
==== Deleting Files \ Folders ======================
C:\Users\Mel\.android deleted
C:\PROGRA~2\GUT1655.tmp deleted
C:\PROGRA~2\GUTBBDB.tmp deleted
C:\PROGRA~2\GUM1654.tmp deleted
C:\PROGRA~2\GUMBBDA.tmp deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~3\OberonGameConsole deleted
C:\Users\Mel\AppData\Local\CrashRpt deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [14.07.2014 22:56]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04.04.2014 12:36]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
F6D12679B9112358AC705A1308156F59 - C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
6846D2CA7E1D5937AEE3F99BB7F5464B - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll - Shockwave for Director / Shockwave for Director
DAD55CEF682EAE6FA7B4C9487563A496 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll - Shockwave for Director / Shockwave for Director
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[14.07.2014 22:56]
Seznam Li\u0161ti\u010Dka - Email - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Seznam Lištička - Rychlá volba - Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
==== Chromium Fix ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{084374C8-FDA4-4D3E-864A-B0F8BCB57792} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13906"
{1E29C3FF-5417-40E0-858A-D446E2CA26FA} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13906"
{8E9CAF1C-3613-4352-8C81-74F3400FE651} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_13906"
{9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_13906"
{B64F33CD-1636-48F1-922D-87C14747AE4B} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906"
{C1916D8B-B4C8-4901-98B1-D60A87C0A846} Bing Url="http://www.bing.com/search?FORM=SMSTDF& ... -SearchBox"
{C3D720EC-9215-4F88-91D2-D0EA71379EB8} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_13906"
{CB72987E-FC28-4A7A-A397-158251779E83} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_13906"
{D89ACF06-CF05-4B31-81A8-F6F05D028724} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_13906"
==== Reset Google Chrome ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Mel\AppData\Local\Mozilla\Firefox\Profiles\gtm80pq3.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1331 folders=128 57051414 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Mel\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Mel\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 24.09.2014 at 15:38:35,57 ======================
Re: istartsurf
Poprosim o novy log z FRST
Re: istartsurf
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2014
Ran by Mel (administrator) on MEL-PC on 24-09-2014 15:46:45
Running from C:\Users\Mel\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\Rezip.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\avastui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2703752 2010-03-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-01] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {084374C8-FDA4-4D3E-864A-B0F8BCB57792} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13906
SearchScopes: HKCU - {1E29C3FF-5417-40E0-858A-D446E2CA26FA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {8E9CAF1C-3613-4352-8C81-74F3400FE651} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13906
SearchScopes: HKCU - {9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {B64F33CD-1636-48F1-922D-87C14747AE4B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906
SearchScopes: HKCU - {C3D720EC-9215-4F88-91D2-D0EA71379EB8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13906
SearchScopes: HKCU - {CB72987E-FC28-4A7A-A397-158251779E83} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13906
SearchScopes: HKCU - {D89ACF06-CF05-4B31-81A8-F6F05D028724} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13906
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C932B377-4F63-4734-88E7-F9A326CF1CE6}: [NameServer] 80.78.144.6,80.78.144.7
FireFox:
========
FF ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-07-10]
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-07-02]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF Extension: No Name - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\extensions\sepherdwilbur@aol.com [Not Found]
Chrome:
=======
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Profile: C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-24]
CHR Extension: (Docs) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-24]
CHR Extension: (Google Drive) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-24]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-01-08]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-01-08]
CHR Extension: (YouTube) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-16]
CHR Extension: (Google Search) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-16]
CHR Extension: (Google Sheets) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-24]
CHR Extension: (Google Wallet) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-01-08]
CHR Extension: (Gmail) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Rezip; C:\Windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-14] (Symantec Corporation)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-10-15] (Windows (R) 2003 DDK 3790 provider)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:32 - 2014-09-24 15:17 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:17 - 2014-09-24 15:38 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:17 - 2014-09-24 15:30 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 14:39 - 2014-09-24 15:38 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:38 - 2014-09-24 15:37 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-24 12:51 - 2014-09-24 14:47 - 00000000 ____D () C:\AdwCleaner
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 10:41 - 2014-09-24 15:47 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 15:46 - 00000000 ____D () C:\FRST
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-20 12:18 - 2014-09-22 20:03 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-20 12:17 - 2014-09-23 09:06 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:23 - 2014-09-20 12:20 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 15:47 - 2014-09-24 10:41 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:46 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 15:45 - 2010-08-09 21:20 - 01466751 _____ () C:\Windows\WindowsUpdate.log
2014-09-24 15:44 - 2014-01-08 12:00 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Seznam.cz
2014-09-24 15:41 - 2012-03-26 21:05 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 15:40 - 2012-07-11 10:37 - 00004184 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-24 15:39 - 2011-01-28 18:06 - 00000000 ____D () C:\Users\Mel\Tracing
2014-09-24 15:38 - 2014-09-24 15:17 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:38 - 2014-09-24 14:39 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 15:38 - 2012-03-26 21:05 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-24 15:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-24 15:37 - 2014-09-24 14:38 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 15:30 - 2014-09-24 15:17 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:29 - 2010-11-09 21:22 - 00000000 ____D () C:\Users\Mel
2014-09-24 15:17 - 2014-09-24 15:32 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 15:13 - 2013-08-06 07:34 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-24 14:56 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-24 14:56 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-24 14:54 - 2013-04-08 11:49 - 00000920 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job
2014-09-24 14:47 - 2014-09-24 12:51 - 00000000 ____D () C:\AdwCleaner
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:37 - 2012-03-02 08:30 - 00000925 _____ () C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-24 14:37 - 2010-11-09 21:53 - 00001118 _____ () C:\Users\Mel\Desktop\Internet Explorer.lnk
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 11:54 - 2013-04-08 11:49 - 00000898 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job
2014-09-24 11:27 - 2012-12-15 16:48 - 00000472 ____H () C:\Windows\Tasks\Norton Security Scan for Mel.job
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-24 10:10 - 2011-07-08 18:03 - 00000000 ____D () C:\Users\Mel\Documents\záloha registrů ccleaner
2014-09-23 09:22 - 2010-08-09 21:43 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-23 09:22 - 2010-08-09 21:43 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-23 09:22 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-23 09:06 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-22 20:03 - 2014-09-20 12:18 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-21 11:10 - 2012-09-16 09:07 - 00002241 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-20 12:52 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-09-20 12:41 - 2010-08-09 06:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-20 12:20 - 2014-09-19 21:23 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-20 12:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-03-23 17:25 - 00002471 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-19 21:24 - 2010-08-09 06:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-17 19:27 - 2010-11-09 21:54 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Skype
2014-09-15 09:06 - 2010-12-16 20:43 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-11 10:16 - 2010-12-12 12:44 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\skypePM
2014-09-10 19:03 - 2013-08-06 07:34 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 19:03 - 2013-08-06 07:34 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 19:03 - 2012-01-26 17:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-24 11:01
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:112 GB) (Free:15.99 GB) NTFS
Drive d: () (Fixed) (Total:165.99 GB) (Free:148.89 GB) NTFS
Available physical RAM: 2203.16 MB
Total physical RAM: 3946.16 MB
Percentage of memory in use: 44%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 298.1 GB) (Disk ID: 8A4468D4)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=166 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mel\Desktop" je 527 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by Mel (administrator) on MEL-PC on 24-09-2014 15:46:45
Running from C:\Users\Mel\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\Rezip.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\avastui.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2703752 2010-03-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-05-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\Alwil Software\Avast5\AvastUI.exe [4085896 2014-08-01] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [EPSON SX420W Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCE.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Alwil Software\Avast5\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Mel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {084374C8-FDA4-4D3E-864A-B0F8BCB57792} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13906
SearchScopes: HKCU - {1E29C3FF-5417-40E0-858A-D446E2CA26FA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {8E9CAF1C-3613-4352-8C81-74F3400FE651} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13906
SearchScopes: HKCU - {9DA1775C-5C9D-4FF1-9811-5A6AE6EB6F13} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13906
SearchScopes: HKCU - {B64F33CD-1636-48F1-922D-87C14747AE4B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13906
SearchScopes: HKCU - {C3D720EC-9215-4F88-91D2-D0EA71379EB8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13906
SearchScopes: HKCU - {CB72987E-FC28-4A7A-A397-158251779E83} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13906
SearchScopes: HKCU - {D89ACF06-CF05-4B31-81A8-F6F05D028724} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13906
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar BHO -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shoc ... tor/sw.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{C932B377-4F63-4734-88E7-F9A326CF1CE6}: [NameServer] 80.78.144.6,80.78.144.7
FireFox:
========
FF ProfilePath: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Mel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-07-10]
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2010-08-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011-07-02]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF Extension: No Name - C:\Users\Mel\AppData\Roaming\Mozilla\Firefox\Profiles\gtm80pq3.default\extensions\sepherdwilbur@aol.com [Not Found]
Chrome:
=======
CHR NewTab: Default -> "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Profile: C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-24]
CHR Extension: (Docs) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-24]
CHR Extension: (Google Drive) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-24]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-01-08]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-01-08]
CHR Extension: (YouTube) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-09-16]
CHR Extension: (Google Search) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-09-16]
CHR Extension: (Google Sheets) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-24]
CHR Extension: (Google Wallet) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-01-08]
CHR Extension: (Gmail) - C:\Users\Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-09-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Rezip; C:\Windows\SysWOW64\Rezip.exe [311296 2009-03-05] () [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-09-14] (Symantec Corporation)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2010-10-15] (Windows (R) 2003 DDK 3790 provider)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:32 - 2014-09-24 15:17 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:17 - 2014-09-24 15:38 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:17 - 2014-09-24 15:30 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 14:39 - 2014-09-24 15:38 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:38 - 2014-09-24 15:37 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-24 12:51 - 2014-09-24 14:47 - 00000000 ____D () C:\AdwCleaner
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 10:41 - 2014-09-24 15:47 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:41 - 2014-09-24 15:46 - 00000000 ____D () C:\FRST
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-20 12:18 - 2014-09-22 20:03 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-20 12:17 - 2014-09-23 09:06 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:23 - 2014-09-20 12:20 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-24 15:47 - 2014-09-24 10:41 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:46 - 2014-09-24 10:41 - 00000000 ____D () C:\FRST
2014-09-24 15:45 - 2010-08-09 21:20 - 01466751 _____ () C:\Windows\WindowsUpdate.log
2014-09-24 15:44 - 2014-01-08 12:00 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Seznam.cz
2014-09-24 15:41 - 2012-03-26 21:05 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-24 15:40 - 2012-07-11 10:37 - 00004184 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-24 15:39 - 2011-01-28 18:06 - 00000000 ____D () C:\Users\Mel\Tracing
2014-09-24 15:38 - 2014-09-24 15:17 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:38 - 2014-09-24 14:39 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 15:38 - 2012-03-26 21:05 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-24 15:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-24 15:37 - 2014-09-24 14:38 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 15:30 - 2014-09-24 15:17 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:29 - 2010-11-09 21:22 - 00000000 ____D () C:\Users\Mel
2014-09-24 15:17 - 2014-09-24 15:32 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 15:13 - 2013-08-06 07:34 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-24 14:56 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-24 14:56 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-24 14:54 - 2013-04-08 11:49 - 00000920 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job
2014-09-24 14:47 - 2014-09-24 12:51 - 00000000 ____D () C:\AdwCleaner
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:37 - 2012-03-02 08:30 - 00000925 _____ () C:\Users\Mel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-09-24 14:37 - 2010-11-09 21:53 - 00001118 _____ () C:\Users\Mel\Desktop\Internet Explorer.lnk
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 11:54 - 2013-04-08 11:49 - 00000898 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job
2014-09-24 11:27 - 2012-12-15 16:48 - 00000472 ____H () C:\Windows\Tasks\Norton Security Scan for Mel.job
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
2014-09-24 10:37 - 2014-09-24 10:37 - 02106880 _____ (Farbar) C:\Users\Mel\Desktop\FRST64.exe
2014-09-24 10:10 - 2011-07-08 18:03 - 00000000 ____D () C:\Users\Mel\Documents\záloha registrů ccleaner
2014-09-23 09:22 - 2010-08-09 21:43 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-23 09:22 - 2010-08-09 21:43 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-23 09:22 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-23 09:06 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetnowUninstall
2014-09-22 20:03 - 2014-09-20 12:18 - 00003210 _____ () C:\Windows\System32\Tasks\Driver Pro Schedule
2014-09-21 11:10 - 2012-09-16 09:07 - 00002241 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-20 12:52 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-09-20 12:41 - 2010-08-09 06:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-09-20 12:20 - 2014-09-19 21:23 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\ZANUSSI F802V user guide
2014-09-20 12:17 - 2014-09-20 12:17 - 00000000 ____D () C:\Users\Mel\AppData\Local\GetNowUpdater
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-20 12:14 - 2013-12-22 12:11 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-20 12:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-19 21:25 - 2014-09-19 21:25 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\QuickScan
2014-09-19 21:25 - 2014-03-23 17:25 - 00002471 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-19 21:24 - 2010-08-09 06:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-17 19:27 - 2010-11-09 21:54 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\Skype
2014-09-15 09:06 - 2010-12-16 20:43 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-11 10:16 - 2010-12-12 12:44 - 00000000 ____D () C:\Users\Mel\AppData\Roaming\skypePM
2014-09-10 19:03 - 2013-08-06 07:34 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 19:03 - 2013-08-06 07:34 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 19:03 - 2012-01-26 17:25 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-24 11:01
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:112 GB) (Free:15.99 GB) NTFS
Drive d: () (Fixed) (Total:165.99 GB) (Free:148.89 GB) NTFS
Available physical RAM: 2203.16 MB
Total physical RAM: 3946.16 MB
Percentage of memory in use: 44%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 298.1 GB) (Disk ID: 8A4468D4)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=166 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Mel\Desktop" je 527 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: istartsurf
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] () HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation) HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.) HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] () HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] () HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File 2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe 2014-09-24 15:32 - 2014-09-24 15:17 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-09-24 15:17 - 2014-09-24 15:38 - 00022420 _____ () C:\zoek-results.log 2014-09-24 15:17 - 2014-09-24 15:30 - 00000000 ____D () C:\zoek_backup 2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe 2014-09-24 14:39 - 2014-09-24 15:38 - 00000336 _____ () C:\Windows\setupact.log 2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log 2014-09-24 14:38 - 2014-09-24 15:37 - 00000852 _____ () C:\Windows\PFRO.log 2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt 2014-09-24 12:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-09-24 12:51 - 2014-09-24 14:47 - 00000000 ____D () C:\AdwCleaner 2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt 2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT 2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe 2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe 2014-09-24 10:41 - 2014-09-24 15:47 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt 2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload 2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe AlternateDataStreams: C:\ProgramData\Temp:2430E4FC AlternateDataStreams: C:\ProgramData\Temp:268F887D AlternateDataStreams: C:\ProgramData\Temp:4CF61E54 AlternateDataStreams: C:\ProgramData\Temp:8530A643 AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1 Hosts: EmptyTemp: Reboot: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: istartsurf
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-09-2014
Ran by Mel at 2014-09-25 14:45:07 Run:1
Running from C:\Users\Mel\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:32 - 2014-09-24 15:17 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:17 - 2014-09-24 15:38 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:17 - 2014-09-24 15:30 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 14:39 - 2014-09-24 15:38 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:38 - 2014-09-24 15:37 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-24 12:51 - 2014-09-24 14:47 - 00000000 ____D () C:\AdwCleaner
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 10:41 - 2014-09-24 15:47 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UCam_Menu => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => value deleted successfully.
"HKU\S-1-5-21-960952882-3187940223-2238644844-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f8f083-9ad9-11e3-9bc2-001bb16220c8}" => Key deleted successfully.
"HKCR\CLSID\{b7f8f083-9ad9-11e3-9bc2-001bb16220c8}" => Key not found.
"HKU\S-1-5-21-960952882-3187940223-2238644844-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f8f094-9ad9-11e3-9bc2-001bb16220c8}" => Key deleted successfully.
"HKCR\CLSID\{b7f8f094-9ad9-11e3-9bc2-001bb16220c8}" => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation) => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key not found.
C:\Users\Mel\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Mel\Desktop\zoek.exe => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Users\Mel\Desktop\AdwCleaner[R0].txt => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Mel\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Mel\Desktop\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Mel\Desktop\JRT.exe => Moved successfully.
"C:\Users\Mel\Desktop\FRST.txt" => File/Directory not found.
C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload => Moved successfully.
C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Norton Security Scan for Mel.job => Moved successfully.
C:\ProgramData\Temp => ":2430E4FC" ADS removed successfully.
C:\ProgramData\Temp => ":268F887D" ADS removed successfully.
C:\ProgramData\Temp => ":4CF61E54" ADS removed successfully.
C:\ProgramData\Temp => ":8530A643" ADS removed successfully.
C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 44 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Ran by Mel at 2014-09-25 14:45:07 Run:1
Running from C:\Users\Mel\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [msnmsgr] => C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe [3872080 2010-04-16] (Microsoft Corporation)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [Facebook Update] => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-04-08] (Facebook Inc.)
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f083-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\...\MountPoints2: {b7f8f094-9ad9-11e3-9bc2-001bb16220c8} - F:\setup.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
2014-09-24 15:46 - 2014-09-24 15:46 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Desktop\FRSTLauncher.exe
2014-09-24 15:32 - 2014-09-24 15:17 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-24 15:17 - 2014-09-24 15:38 - 00022420 _____ () C:\zoek-results.log
2014-09-24 15:17 - 2014-09-24 15:30 - 00000000 ____D () C:\zoek_backup
2014-09-24 15:16 - 2014-09-24 15:16 - 01290752 _____ () C:\Users\Mel\Desktop\zoek.exe
2014-09-24 14:39 - 2014-09-24 15:38 - 00000336 _____ () C:\Windows\setupact.log
2014-09-24 14:39 - 2014-09-24 14:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-24 14:38 - 2014-09-24 15:37 - 00000852 _____ () C:\Windows\PFRO.log
2014-09-24 14:34 - 2014-09-24 14:34 - 00017486 _____ () C:\Users\Mel\Desktop\AdwCleaner[R0].txt
2014-09-24 12:52 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-24 12:51 - 2014-09-24 14:47 - 00000000 ____D () C:\AdwCleaner
2014-09-24 12:49 - 2014-09-24 12:49 - 00008548 _____ () C:\Users\Mel\Desktop\JRT.txt
2014-09-24 12:44 - 2014-09-24 12:44 - 00000000 ____D () C:\Windows\ERUNT
2014-09-24 12:43 - 2014-09-24 12:43 - 01373475 _____ () C:\Users\Mel\Desktop\adwcleaner_3.310.exe
2014-09-24 12:42 - 2014-09-24 12:42 - 01024790 _____ (Thisisu) C:\Users\Mel\Desktop\JRT.exe
2014-09-24 10:41 - 2014-09-24 15:47 - 00021809 _____ () C:\Users\Mel\Desktop\FRST.txt
2014-09-24 10:39 - 2014-09-24 10:39 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload
2014-09-24 10:38 - 2014-09-24 10:38 - 00112640 _____ (forum.viry.cz) C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => C:\Users\Mel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Mel.job => C:\PROGRA~2\Norton Security Scan\Engine\4.1.0.28\Nss.exe
AlternateDataStreams: C:\ProgramData\Temp:2430E4FC
AlternateDataStreams: C:\ProgramData\Temp:268F887D
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:8530A643
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UCam_Menu => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value deleted successfully.
HKU\S-1-5-21-960952882-3187940223-2238644844-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoInstrumentation => value deleted successfully.
"HKU\S-1-5-21-960952882-3187940223-2238644844-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f8f083-9ad9-11e3-9bc2-001bb16220c8}" => Key deleted successfully.
"HKCR\CLSID\{b7f8f083-9ad9-11e3-9bc2-001bb16220c8}" => Key not found.
"HKU\S-1-5-21-960952882-3187940223-2238644844-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7f8f094-9ad9-11e3-9bc2-001bb16220c8}" => Key deleted successfully.
"HKCR\CLSID\{b7f8f094-9ad9-11e3-9bc2-001bb16220c8}" => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-30] (Microsoft Corporation) => Value not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
"HKCR\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key not found.
C:\Users\Mel\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Mel\Desktop\zoek.exe => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Users\Mel\Desktop\AdwCleaner[R0].txt => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Mel\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Mel\Desktop\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Mel\Desktop\JRT.exe => Moved successfully.
"C:\Users\Mel\Desktop\FRST.txt" => File/Directory not found.
C:\Users\Mel\Downloads\Nepotvrzeno 840931.crdownload => Moved successfully.
C:\Users\Mel\Downloads\Nepotvrzeno 622108.crdownload => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-960952882-3187940223-2238644844-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\Norton Security Scan for Mel.job => Moved successfully.
C:\ProgramData\Temp => ":2430E4FC" ADS removed successfully.
C:\ProgramData\Temp => ":268F887D" ADS removed successfully.
C:\ProgramData\Temp => ":4CF61E54" ADS removed successfully.
C:\ProgramData\Temp => ":8530A643" ADS removed successfully.
C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 44 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: istartsurf
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: istartsurf
Mockrát děkuji za pomoc 




Přispějete na provoz fóra?