
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Problem se spamem a internetem
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Problem se spamem a internetem
Dobrý den
syn něco nainstaloval ana počítač, a avast pořád hází výstarahy. Prosím o kontrolu logu děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jelínkovi at 2014-09-27 18:33:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 736 GB (77%) free of 954 GB
Total RAM: 2047 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:33:43, on 27.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe
C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Mumble\mumble.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Users\Jelínkovi\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Jelínkovi.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: cb53b500f3e90131a6091fb939dcadf40061915 - {11111111-1111-1111-1111-110611191115} - C:\Program Files (x86)\Senses\Senses-bho.dll
O2 - BHO: 092950600ea001325d04029365df3cb90063831 - {11111111-1111-1111-1111-110611381131} - (no file)
O2 - BHO: 68671f62832e4803b34065d441f9a2210065123 - {11111111-1111-1111-1111-110611511123} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Game Fire] C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe /START
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe
--
End of file - 10256 bytes
======Scheduled tasks folder======
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-1.job - C:\Program Files (x86)\Senses\Senses-codedownloader.exe /rawdata=cC/1FM2SL3eO0MQpuHljhymBzdpoV92KDuyVfrNjtqslGPdW2ykvFVbOs/CMHjAL0kNONPcWSTRtO82NGTnLKWjFHB3/XnybEG7BGKJF9bMug4iucMixqd2Hm0PxF2699UEbIbl06NFEGEl8h7KKfBSPEwcCH+kqGBAf6PArIxyV+IEBB9V07YVVzP/uRFeCAf0+W6wV4o7MZQEPV+AmTaQEhZUvpMXbqHP4dK/TjdFJ5OiB7bTBI/YQrSjHbwT68KcFuIsy1TI9bKrqDoxTsIqaJ+pk+TKU535wnLMXBjLQ+Xpq/hFUgV8pe3HoDq6dZ16qCVZ1UaPDggtiIDH8hrz617XM/DitsOQCJl/AOUb08eGIKPkwhdyrTEn/eSBQ9Ud9vnCWAt9wQYeROlRxEIA0VZoVpdPjsmJ8bWA+H/7FYQgm23TvM/HPuMPaLZuY0y0QSSk6+AfrFBVfajf2Oe2nj7HhU7bAiNwvdguNXTq5ZLGOHu2dEDFx08dSY2FZorACikBIQTpINZIAWefWDj83pjbTzkbt6Yum5R8oRCRCzPSiwLQ9W9SVCiPr+dUT4NN/G6CmjGNs24yUesU0j2tywEGjDLOypZXeywgizRvGL+VDvZoHPzajLdUKciB6PGYSuFVp5V6nMuhg24X0PBNgq7cc3mhfhvRrSxGaPT6zHJP7sHjRiXEWXQliHYB6mT3Yv4nwfvvQahA3kqZLcrsKsndBwTXKZqde6pa0ROrJvQtewLrFUs1U30DytnDCJh16TBORKBylSIUoozIZt6FlrPob8+Gym3rv0LZLoMtu3EOk0YZgcBVh2zxesnMSWBQZeL/rgPX7fltVtYhNnEJyRg2Y1z0EzegG8dDH0S8Sfs5lWYLl+Se/Xcjh+T3XBeSot+i3anjGQfUYBWyTKRW0f/Xqmz5WFlFsV73AE8NOSGWu8WST6f5c2CA66uO2ddJAVr5gKFQfdVSfeaqd2UlrdTkaKcUUSnMXIZQ9WDej4eFuXbf7eQmMnszzP5k3RgmA6/aQ4c2ugnVICer91Vs8wJT4fja3p8WDOLodPfpGWu8PG6FOJGVhWMTtPXn2sePwtFCq92DOsxDDI67AjbxA+448W+3xUsYhU08NnKkUPIWKW7ZL7Mr11De+Rs27qFI1V0t8cacWLN4RYfiQXv7VGh+iEomQ9bQQuqV0/IwZhWGvdst/IdD9su3aKIy3U2/xetm8FdsvIzShr+P94v9HoZvJdQ0f5dIBuuzi2ibfr+KBlm+cz2D2WVwfVfp091dfycGHcQOzWiVgEow4sMolM2aDmtL/EMbyFZt++SS4XY2ZgStTNCP8mzNnQOiy8K4yhpzdE27Uszkr5YCiQg==
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11.exe /rawdata=ii96ZW58RmcHjlnuL/NyavQXK+4Gig0Nz6/6LlyxwSNjDv6gh9SPPgOqbIyLQ63TkNLqbyPL5+yNVC1xsb+EOby0FCxTyWeCQ8IDhj0NUYzBy8eVz36qI/oRL0r2DDGV/yrPzR3j/rPME+ACj/FHrdxvyXNJZAchMtFC1XAKvgy16U1KQAd/uSw5OQ9cf2NlILW0kHJLFimpQ7GIeLUvT1z2V4marEvQ0yKSrU7m2Mkti/Dxz29sZjw8B6HrQvPlyNd3Xlv3PnVWBXUEtKqlb/EEjOYnd+PmvZJNXzbz4ZuCZERTsKkSGYI7O2YHoK24/yG4/JkG8JCJcdQTMJ/R4mFjxUhVitApOWlsDnkg75uevGTtLE/iR5ZLn047OH+Jzic4oObCBU2G1S2WllNBYURaMEtW/cB4I1Mh4em+CQJkzOxhDsAuuNiJtQ3cUsmCXBU0e3CQ5qxi3HcWQNtc3dLwwoc7FBO0CX0Eh6cO5n1qDZl1I4Tw+x/mUYxsSsJqp/9upcFkFBK6HEKzDAFUVPP6a5519TIn4yLy8gC6fj+R3izPn1uewsVtpibLKqW5VWCanR0CSwg4050x8DPV8gSM+BiPPQVUE4lV5RuadJ5m6EuPg80jeDBKPT/B6yB8WIOraon+5/jzOYQYXQ85MDWQHU/JtUh7k/e4IHtWyc2myvUwCDsbpmz5swPRsvNEErfdPd/4bYfxyB466U72ml1rcZC6wS5ZJNyJAHd+xxaUMMcP+z1vKe49rnsMuEV2EbGuv2xHJn3rt7pSif06I3xeHQHYaBSZJonL8IyPhEBXUVgzL+BdqPJgyPMLfyypXnfyAOiGnwY1ySxUISDoTAR69/ewqpuCY51+eJF9E4DkOmmZU2vtOB0fPpaaxaKeqL77fcetyrnkx+qzwyIBHCb3muwKCsJrWWVRkJz/BEaXuVzKkMbSFngQyqEe86FhBm0xs1/roAa60nTIcRzzTLgsAefnUA5NUaTV7gdMM5i3uVM18pfKmjfBs6Cp4ANtc4qAeeQww+W3kY8uHik2xXRC6EyRosiL0Sm+XK57yudRbA2Sbx5JcjU58QQoM93vd5oIMYLpY9sEoL5T/kXC26OJdQG+d9rT4o8rrEyjLBoPqbRgOOaPBfCzpxTj52wXaWSJKqoSJr7CMON5qTUUzbaPIV10wxYr4LcYbDBpRTANEDVxq3zgiSrhwJgSgc7plBXTcZnCSzilYqIYBNUW4JtvmN3dvVIwF/6zzXADhfG0PkmYlQhJYoXV1ZYneBnJH0roN7x2FhIhFyUxs0KL/s6C3D5q3lt8LXmkxgLqRkA+I3twFjXTiOqAr0vC1pimizIhF9Ohpo+Me9gjar34DwquP2W9TVvhM8aP0h8I5oyDiT9rhYpY6ls40Rjb/SRlFbshit7qOWXHmWJtESMiuxbIJBpx+EfTQk2h9u7GGD7kMJGWyxRMDKi9xgeAVKwa7vz8Mt5BHTn/eKeL9WaheIUxfEQFnbcGKpSdgdJh4WNYzpcFVXa2PEbrRVpNUyDWuIGqmobJkKa6TBspSzQrNI7aOCcsWWj8UZhBzH90BtvCnviIKhuYIT3fV1S1WEfEo5RZb4a2jbFInNQnw8GebWB26I+yoTGfQQ+5s6MQuk6sO5FDm6WcJM16RSCxc7FMNGATUq9D60Bw6TC+xeV9TRZFGkApB/frhTAsMs8CkMRFyXT2zSP2SAHLaDJHgsnDp16x12Ykl98mpmghs5NKC0TaoV+1CVtD09VVge5v+Eow0fvM43EEajRqChsyj4s/QSvmNUEU29qlHLmd5NwkdswGciUkumEPOG5l60m6ezP6LXe0TP68P0O+i/tMgY6BDdZRH02+LjeNjMq7jDuwOLiiNg1Ft/ollAyPRafSuxDNscn4Psm9sc9VP8W8ys7XDMKCFrIaG4U4OFtywuxdnV52/Sp2b7hWLrbM9UMiiqQIu6kz0v3nRIM0+CaTtAab3oZRq+/YedZLvVwHucRZhMHIVE9e2zmH0XIwfC+q2kf+Z36XI5LJ70aKnHD/SiByuQyugDuexbNVEopPBylF5hwby7LVV5S6ZL2BAzJM5ztF4DB9ZFSaMQEm13NtL1P8n2EqsmS7270A8Fucy9WvsEHfWG+hYglJnyJy41WbhG0Q6ccqT+90fpE4iFqRjiym7zL5YCIOvPPp5tP748rSOvjCV6jlwWweST/ugpO/YaA=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2.exe /rawdata=jQAV6IpOUbQwfKUudi//YLnCMB+YyiLmvBH4WDXuGZcZx3fBKkfiTzEbH5K3h1d3Ru9y4ApXGMeLnuLdOp+9cpTB98NjqGh13VrpfsPT/hCuBVQecAKRhKFsAhgsPtyCwZ26ZNU42Na4Mm/qjmKNCE1gTittdgZr6ERm/sMxMS04C8UAWTQveV2NUb8X/KSq4dgumCTfgmWEe0hwEwfp68qUNarTG9BFH00v9QuT78ncaFTBn4InZKd7jRPTXAGzGnDnU8hHHcBCZbbv22QnNQhHKpoBACTL8ciHfnZTEPG9ttji6x0mPLZ1Bpvqm2XLVYC75nkmuF0ojpBKjw/3RGcOH0Kd+6r99OSJWik9+lNttpFjjrtW6eLGl/Uj97T0S40RM1ddzOLacocWGIIL276xBsx5x20Rz/JQ0U2NUaO0nbswSRf0IWcc+VoOQQpyfq2JJk7bQ8fEiFx0YuH4vWWOSuJpzWsBftRe9lugENSjEIk6JTWp+8b2Y3J0s0bQMBC9fk42fHcMPFoDN1xbgPIsK2rGLdvWNXgkVKLQmuBNcH3uWzU/nyfIkE6Vx5n4cwxpSOyT2cq906necahREDpEX/2jRkCs3OFlejfcVZjjAgD4fm2b4yXu+oZWzdIjTH6uSLQdcpUHMpBiCK6rANaBXn/aLWE4hmkN6kfjjXst0GGf/D1qDVhnvZJkxYniDWit7+LNH81DIk9ockSY4OVreSsTuA/y1GZv0ghVX+QUeIMmcWnCmVm6bTESSnrkPooInlNKDsbyEuhHP0AGi47CEnH28ShB8D7NhT62dFjDLRwogfTU3kLu7ccUFwJEmgz6v1eApBwDvtTFVQVz9hxszqm13Y7gWoYx1t1KkeiSqm7tjCcDiYJmoigzefmYfE0kp8HqEIX2SKU082PEJ6RplPo9ycoeMMoQgNh/tHs7Hco7Tf0rcydDbrv0mGCzH0CyriwMA9W+s3VyoMV7aqFvk/UcgvsnFCaSKgvfZLCkSXhrtf//zwnbv671BAIU
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3.exe /rawdata=qKkvtzMs7i3IZWi4cLyfiVXpathR2xOn0QRCmLviV/k/c4dtifX9yIBZ4JcvCoQBzcEXer6O03cFQPI+zE2SnI9kj42tUsWCVfGJBJqSr9sgGKf7XscZOLJbCg15sUPLWjiTdPVr5dCToytOl1NB4BIC1wcdm5vGD8FrtxkaM9BE3x0F4kpD/R6VLq3DGRfFH8v+P6dryn0IuJV9CBTFai4uq0eZdhx5FGFtl4lkdm1UwggkvuizkxgMKwKXNIYd+Zx/xPbXy7bP4jwXo6+HQP1JFErfcsuz5ty4sRcquLqpSn3QD/uX9wD6FrTrwKwYz9sGF7IiF77WNCs6gX3yDG5WRQPE4uQqdF/TLTKdBG2kQBwzwqNFSSwmkrecaWCk9/O9/GZ7q3Up65wPJGu+HPY4oAtZKRUM2oHwIptooCj4yr2gkwgAfHGhUYb8dIufcVqxu6G6qTooFjz8Tvl0FXRcv/K2Zt+kGd9Q0nWXs/om1sQSU7wCKoamZMBxFPItYe9SaYIfXjJB36/FMwCZrSBzr48wK0Btwlzw8aAvkq8qfCPgeCOoZ/Ko5adK/VVOj5rgos1Yb/8X0d8zQQ4fJuZvzjC3V5lLmA+1StvbhMBKKBCUCfMhTX17zfm7E/8cPCl4XZXaPAus80JFzlbCyPjGx3PFmwqaCz7rrHDbku8YmAL1iZA+NLP/+bl/Jw9C1o9a9xNyMfVlA8ROS+fKXtwSMDUjHzAlnekvhHRd2i/D6MKBmdMz+wydbzHZ2UpS5Pku4zqOInRdDv3oewgd8RgWUy0jqxCjhxRiOCgbHJexdPY0whty/JG40DsST5iEUYkr2wS9b3ijzl3OnXj/vwfACE82Ky45W9kxLeSp6Yulhs8ZiXnafHlXSv9JRXistfehHTaXCkivq/06RUONSg5cRD6HGcXYijcewX9tcAa5ZD15e3r7tnPcbe9YnH2yWT9vbf/Ym7OX2ULVtxdmVZLOVniVNtBbzkB4IfgDOi5VKtLuWELkDlCBjkgGr9ylSVIqzgszooEm4S0Bnj2tJ/5uUoOjERyXL0/BEsUHHQVUGsTTWPy5EJ3zudU6TRMq1FbpCwCrxNWfgRDNs18WOevI6uFQlB68wiVY9+v34tZjWT3Jw2SKCLJGxO03beVAm2TBcsxlJcAfH6rXhudcjb/8ebj6aPIAHJ8X4/NyxIgy+KiUKFc6Y14FIN5dKl/0fyCAOwgNNwGwbc9HqFjuXq20Epxx5iSfL0QvcJ2Ihzr9NFhslMSxLhSpOPHDLWo8WFIgNUAcNnaVu0kMbmPWti4WMrA5zFjMPTIhKz/c2q4YeacNpcvQvyo4/9uZuE6RNw0hPDsFHd3pkdq8uM1lXQ==
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4.exe /rawdata=d6rTfWHi3Xv/GFuZ9TZWWlgWesE/r3zk4rFLQ4u3V268d9j1+KLX8EUekAJSyOJon9WM8VjNuJXuE1rGitJprGOOHOhbIVliOMKq0A0Nocu4DGiki3qyI47JTGclmq2oon+w3ilTITNA636aHE0CyrX999rqDCRB3xJd6dS/q3yb92uX0oE3NWBB3rtW9h9uTuW4AfnSqMfA1EdnVRPvfIkyWbjIEy+IYSS/kqpsTKxC7pJT43UfimPXmdhA17qWBd1pyWDXGCEE9M1i9OjTDN9JSnOR1RSQ8iHRsuCs1TGYa0AVyFB4qx9RXpspZXCrERAqk/KjhKROf1zwFeERsUxt7N+8XwHo7O+ohrcVrLsbZLPb/OAxAwUJQi9lY5SrJ0PeY5VrQHJp+ULiyTyOABOmjWdBc78672zxh54gJM8PbENwkUFhAexeJCl0nW3uh+qMa9t4zF//79g85RwWQah1tB5qVGhxQDZj0hYXG6+iRon38m4lGgUqk9YyFeo0jladyeFMDHvBEH4gjZCF4QFNrQuwbmYIEkPOSxN5jn2FSu8gtP6BdtxWMyxb+0MCbrKV5/JnAm8sR7TmFp/WLbwre77Qqgk+Flx8I6ad6bPfLYMlhq2kg2Zkeiw8tTH9S8t3DuhUK9UGBm97GAC8OLFcLCFx5bvnT5PZBzDmLzVg59j7oKhcGZSDo8GOpMr76vPbkMtXcO8X8iRh9coJunC0fMTQD8JGp3BCA3I18lXljAfKaTCn3O1eORNmOuziVHHO+BOOvoTZ97yozD5HK6eiJ+AdTAYhHALsluc8riwtdyKcsqiRM1iOVhOXaiqbX6xNDurbjrESDm42l6u3AHYQKwTfieXOA5D9lBFWM6NSLp6we5hDsQMXGVpaEsKfeXAfULdn3h+hvDcC5JsCJdwfwishs8Vm0easBRnrN5YztE1VGi5wR7A9UTdBaITMYiI2XvS4k7ISKh11shyqmbEOXNzIf32tXdN0TQD4OjWSq0NP+1ozzMJF2rTjZJ80FXg0BZSma0PnUbmZiI1xvGNd9dsx1Nb8bNUMe6Y/QCb2bMYXdfqVcInHYcEookpZVvMJF36Q3/7p9C1Av00n5Y66rKcKD1J7p3DFFWXtWvHd9tdQBVigj1hBOlCSrlKCYZhDyq3F0jusOjL5SQLR07WKNWOEP5U7wrQ6kckraipSzWYL54NJyZzwTJCmZvSY6UsiO588LMfm74frpQQmtgBrURrDjn3O40birtLTzEMqf9s+zjZTzm6Y1w7CNgXy08FkJLUg7H2RKDEPCqIPAt7PIFxDcvxVE6tjv3xza54/QgwGA/OT8Aic4WUbj2FKD4UMFvgKZMoxVTN1i/YnOZwfvNqQy9/dhgSZ5iJqvkHGrQjETdtjG4UdlFNLo2ycwapVKaq35zLruvyIuGxU5edAI5KUrXewW6j65dl90o889c4Hax2mKDh1JtIOVqRgyBSaV8OEzromYO25KpSVO4UOL9e+QwveqKvbOEE3X0Q8dlw1j9L6xnV80bbZGr7jGxLs4rNq+T/I7fbqpjJ3Fx8ioy00OZae5/DBb+QPrQ7oU8xaZFBhV14nUAEjPRwjqFzGsKCWjm2xz+89CqNkJp2v7mFSMRhfFQquVN6MepYQ03IyUjXrpg2hcpbrVRXP854x6N2gY1K1G1fy1QIQwzzrr3r5eSgMCzlkc4jC4jI=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.exe /rawdata=dHzdosvHrxky8qGWkVc/qLKyEiL2WLhEQS4ptVi4uOQJDiLrIH9rJRxTuCQvRexMAW/Ujza8xDe1g/CoH5+FLH+GDjSW0eJtXolj5jFIGZrzP0n1DWvLe3IOMGjKzuobhP4G9+rbaQy6yMrprMTIpxwgK4SbKBCG/mve6FFdpB6gho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spYRUMdmb+TmzbKZGTN/cdQ4lFcPhLhOtnKaA7y20uHSKUUL7cUtrNTbQBPI7fQc4d9ieCGKuI16ZPjOK9DqhFd0+usNnqydSPhghcAbgptgv6qdKTzuwpTRaiOux1jekkmjU544HxT042UMP7FVAhs5ACwTihOrRVbrdYEOrkWDRCX1wvO+A1oVhRe+CnH3SHwhLvwE6BLHU5KcHyLcQAea8ryAoI7Af86c/mc6lpKmVj9FeOZWAa7HrGgH5l7E86WLC/s4I0Yy9CwGmkRYH95+8k0bkpLK4rHaJyzV9vJV9ytivobPI+3HbNISYYDQ+Jx123CjC6AEHYEAhv5dnudCZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBhKSSJX9sKO0ZC7f2bUGFChYXmaJuYq4aXxB/eWwbhQwERU07FrgR/C+f76+kz6XahEF1VCiaEH/UmXD/C1Ptv+So7K/fLHm8F4na3A0SX+s/xQfAbGGr8h6/5qsAw6YKwbfoodC6aVKm9Ri49UsxN6f2p0XoOq7Ybf3wzOW4biY=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5_user.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.exe /rawdata=dHzdosvHrxky8qGWkVc/qLKyEiL2WLhEQS4ptVi4uOQJDiLrIH9rJRxTuCQvRexMAW/Ujza8xDe1g/CoH5+FLH+GDjSW0eJtXolj5jFIGZrzP0n1DWvLe3IOMGjKzuobhP4G9+rbaQy6yMrprMTIpxwgK4SbKBCG/mve6FFdpB6gho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spYRUMdmb+TmzbKZGTN/cdQ4lFcPhLhOtnKaA7y20uHSKUUL7cUtrNTbQBPI7fQc4d9ieCGKuI16ZPjOK9DqhFd0+usNnqydSPhghcAbgptgv6qdKTzuwpTRaiOux1jekkmjU544HxT042UMP7FVAhs5ACwTihOrRVbrdYEOrkWDRCX1wvO+A1oVhRe+CnH3SHwhLvwE6BLHU5KcHyLcQAea8ryAoI7Af86c/mc6lpKmVj9FeOZWAa7HrGgH5l7E86WLC/s4I0Yy9CwGmkRYH95+8k0bkpLK4rHaJyzV9vJV9ytivobPI+3HbNISYYDQ+Jx123CjC6AEHYEAhv5dnudCZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBZ63JyCHxp7uqti/1N+3Zc49+hGDS7xgdqcSa88eAc5FAyFAAzey/5QUMBLnNnFPZA52rWgnwWQkzuGfX+u4dGX8GkJxqxvOn5f1G+sj6HAiUqNxn+SKzUmX25uFGB83K4UMpaMZdw3tEHTlUE5mE4q+2LImMIxSl6eo4wYj+8kI=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6.exe /rawdata=tny8MLM7S/WdZVvokZmCBy1UUrkqReGE0ZzALK6RRQHHr8K5weHXx3gMD4IO6b5ZUxNyGlFh5lUOliilPx6AEXktGSGp8lH7JIbcuB3XirIPVIg0AsqhfetjU0bR21CoEku6kQ1tTOEvqr9njuUiRH14SFq3bQG0+HBfksZofP41P49pqpQzKLYs3cTcm+8ymZMmlhQNqnx8NS+Tjpqo/U5Ir3rZo+OnbJX1UfdO+jWXsBZLeAmdWxZzTMcP5Q02bNBwFNyafJgX0v1pDO35flCH+PWb7pigoD73Ni4SwMkeD8LLatj+xkJ3TE6tEhW9kvpR+64YW0nOUKAkt76jSz/c+IWUTvVvbM6m6BLW4cxTO3VBA227QhTJ3hKQSvKlHtINcrE2g7cvFKwQQEKh0m9p9w33EfCGtE+T87EaOUROYdr0VJHMazRXbeRIWDKq2QNOSfgTblKXpv3iA0fcwU69L5IKqMLNQ6txOmzvJXUpIyGsRTmMEQotBDhPRXGPRx5yvOnpm2NuhH6DX8AnG6BI93Lf7J45LfMpORQ1ldmXR6JuBJOar7eQILwYo/mATaGzotAWHwm0IhJWm1gYsMQvhvybTOO/GvsrGsUDj9WolK5mW7Ofor0bIGErCiixDDWpdKOyZyaqaRt88gr6MlGRLMbdFvKEEp4F0KIuEgFGhe0l99RAaZ8oX/gJVcq1XHdfq3rWwJdK4jVdhvm49jnN+WFDzAB2CUqXqSw7IX+pzR8ATGSMzoY43IKsVGJhVbjfdn/6I8TWiyMvCYywzn8II5vmhliTwmuJrxwkKjkE4RsOBOlYCPZFhZqfVlMiW51dVZG8FcPPC96iAVKXnK600YxPDtxflWJKyYLpX/1VJ/tx4x3kR5xn8DQygPXVMU2pfWL+B2dn42gDyA7LzEsp0cIaK1jZv7KikoVANC58nmGxt/v8IYRls6Np5VHE0cxRmiOf47uiQ7B4xYCPYSJ9F+BT6Goq9bCby4jOHnGzGgWV2cZmLOY8+TiF6EyRWjSXrFQFL9xS70USKvdrHV3TM3IDdsNplAfEz/qHnW9Y1aqayskNUUnrljVG0FVUqhwAWSjI9DduCs9surq5XvUd+Y50I03uq1QEbhQuS5Gzu2qUlx0dc1sRoRbgeN72E4Mz/y2vofKb1be3XRZC8D+7GrIWFbaM6Ogzkp27DP98HxmCXComkElDvSEjDRQcqtwTCU4aYWA7e8/Tj44zk57xK16Avnw4mBt/BELtKtMJaRvfTtb5ZgcFR9jqYOBQ1dPB7BgqPPtRghAr7qhiMDyBAqWfr/Vntl6BvCsE103qKjLN88TYIAJhB8enKVyCLjtqmSd/zGvJvEkEzMaTKz48kYCGfwVJhRkpx77kiRTF4ApjRRSZnkxtmL+niPSd9ORBpNW5wnbs6amlugG7dNTN5kZNUGNAhQezfbPhKXaantJAEHNpUCymQY8j0I9VCxkAJCBA1japfX96FkQBqxt1CJpLUnDoUTVH8QdKouZlfUXn7ssClVLPYxFELB7ttoCqNW3awKQ7iXbtbCXak6uhVtR8M2p9oVyaMyEPaWkpaBo06zF3D88pviwMgwoCEqI7z1JA4uMVNZh0EK6SWt4FXbl3s15o4lclIb3XJI5sGwQkz0i2Qn+/ei+18ecJRCqQMArthze0Ih/EKCUHU3nFIEnEULdjrLAnbLn7pZo=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7.exe /rawdata=ug1WvRJuQjHJqGCmGSwbEBsXg4rm0OjGyXMAitApLT1dJFPlVri+5Xgqi3onUssBf+yWXJNkRkzL76QsoDeZ7dFQR8BSpH1DhBncrQUwyvXi6wsDVUR3CfR1rmPQn9lz7xDq+yCdifaP4/v2NJMvyp1e5heKOfoM5kJzYR9VCXpIWaHfT5Mqq79D0CtmC57QhQdhKibbV9LdU0xahg9Hz6/LfAxeDpJ01zgW5xp9+xpT8uC9cBsYSMLskyk3XwmAmKB9J8f34TDWAyRmKZCZnCnQGePkoWTVzcKtnSf3zn4m+n+AciO/jdwiv91mGARilVpRyA2HfCFMtNdyZAaz3xh71iHDKQgc12ensoQZcnFY/urJSPuRiNtj/5d4WMj5dhOfmPwavKSJtYQSLPjqWDCR5GYELzwmWN417tBwPI6lDbExRAPS4/FKXF0t0zU2o2EnJvRGTei7oGYZgKMUAHbMTXoZ+FBpXLFUY0zZyL28GmYt5OPtP0y6LXW8sdwvlKN9Ug8e7Q2nOvElbB+6ALYKEO5suRoO119iJ9/OSoLCHznQSWh5s6jrZi/EDZ3uxCXSSj2g0xmY8/brHnLK6lnzvqeFgUljox17HP41X+6wj20bkC7nW9bplZu9Lf7slTEMVkm33/H+pHTR66rQXZEwKgAGNBzEYADC3PHjNMRvpWTMegZ/wlfPZcsDw9Bqbc2IQZO4KkrA7649LJtElksTg8GM7TQ5tpXBinfi298nMBjq8P3NsXgQ77s2vUYpXhe1h7ZHYjMPuTfyAuJ+IMPix0LHcolki3ZPJWlz3TkfQzJ5NGmOtRkhITaPfmmF2Ws9T6q+fn1ESP3CrwckviqWwEDZLMw4Etd1Sckz7jspKPnw6Uiry7CT3NfTtG9Aep4TCs8r7ZqPefq+RURpi0EiIXgn15h71GDAyzhAhoVE9Ihmy7XaHOGKaHOuO0/wsrHGJzUhhDClfPvjd0m4uuFmkZwvlBS1IAX6gLkxTOqmtC6s/nGlXL4WIYnO8p+aZXJbUrNWCLQC0ZEZlOD97T7wzSEe9hBDdNsQr/HPUl55/hQCWd4B6M4yfFmrOjFeBfR5veK1ALShpCVAsNWseHCtXVKYTBqAmGphFlcTitjGRRaZzqANPZUwVEq0fxe15CELdCqkJQ6DBRo6gtAhj/pYR10M3sshlvyZ/Umtt4w+Sd83rV/MilHwiqBHEhm2cJaKp/ZxbnjfVFjAA2LNotJgr3yXdUJjGga7+xWCT9DQ/AqfE7ao/sRI5v2L3TzX++/GfL58+YoKaPWAKoQ6EWLjC0PWY0eATWyAkeohlJjIqU5NQobqmW3+HmJT7vhqpNY5VGJYq15bWlHydU2iSkl1pb6cy2Fa25oATdhd1D2oD69YmjaNlwbayWKxP3TrX2gKGwv4S+SwHY8T99QD78Tn+HLKHtTwXn2gLs0w9uuYljmF+8PMpCHq6CTN5j/K5+fqau/FOj0RwvKTN7GqEz1cQQDhA4DSiQ2M5gXaPFDE21x12hNJWznKr7n8M4x8
C:\Windows\tasks\526582f0-0aed-4e27-94ec-b1412802ac90.job - C:\Program Files (x86)\HD01-V2.1V16.09\526582f0-0aed-4e27-94ec-b1412802ac90.exe /agentregpath='HD01-V2.1V16.09' /appid=63831 /srcid='002128' /subid='0' /zdata='0' /bic=0F980A9FD14A47009B5BF997C147A026IE /verifier=ec13f6087755a72301617a4cc545279b /installerversion=1_35_09_16 /installationtime=1410889102 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
C:\Windows\tasks\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.job - C:\Program Files (x86)\HD01-V2.1V16.09\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.exe 002128 0F980A9FD14A47009B5BF997C147A026IE 63831 1410889102 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HD01-V2.1V16.09
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AIHGXB.job - C:\Users\Jel�nkovi\AppData\Roaming\AIHGXB.exe /infocmdline=aGKpGXQyaHuDDbaxcI1qDYXTuZAc/rvy1MP0q34VzZZfltwx/vcoXOYD6F82Syyj7cnWtimwi55Rz7AQTtmbvgGy0exQjeEKr6p985OalzPYhF/QuIL3qqPfXT+wgx95VCUbvXXXftZHq5j2u74jrLdEFlFBiUhSPf6Yvm/sI6Etsva1D29GOUgSmnIuETlCHCEI6448YMd5dbITRnbPmqVHn0LM0Yq0vuaeTkYPZYGD46mOHhFY3ivsEr/6bjf1KOEqDX2lwyp1lvdfrVWk4oSTX2Q+qPmX+T2dWOIiX9sMH5uV7lyOsCeanbaVJOA4vp2Ish1SgH8P+89EoxAuPH7xsmqpNjsVRCUdgMQs99O2bT7H8PRAepyWDJc3p6kgQB0m70nSTGSDC7tGUUS2yQe7tmw0L95y3DQuB2RT1oWYOSo9rQVVxXdxDFQEwr+piY0+pCStvrfD34op4jLkbUDIfjPSJVJE64EJ8ovTzbo78c/gp1SxzEngrd1x8eZY
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-1.job - C:\Program Files (x86)\HD01-V2.1V16.09\HD01-V2.1V16.09-codedownloader.exe /rawdata=PfWc1PIGXrCCRe+9s6CZac+QUg5mu9AycbpLZA9BABi/GIJjiFG2O/+v5lrWr2ybNywj1I1ym2M9QXVa/0H1olKz2Pn3ni1nz83rKcER2E1L4bqZsHZ45equNiqO4DOCnBwTb+9p0vWU+IzuOuvLiKMwL1Xu6bZ4jGhBF/O5na5b0ys86qqf7HvrQVjXAhOAsniV6KFO5xk1VEeGLeAduQStxTMw3sBUR+VTBWYGJjzpxASj+OPAnP3pIyPljKaZpquMPBWV7CLuYPs2qZhI+nX2NVoQm3a5shRXP5AqfeQMEE4fVOVZUot5QzbwdkH5tQYz2iiNokmvGG6YwSD9GB7gSeQf4MwcJvdvox9F4woaEpZHMfbsLET9ozSqQwPe+poCzXikNknTc80Tra6MPuUERTiKHcVpWSdkFIQx7WW83c2Yo8y4ps6v/XqXNIwUTBySyZyYbD32V6DT4haTNybIscfxv8yi6MDT54wdVNZ/lDingAxf47HCeWl9tsRQYEACwRR9FKyPBsjBifAMWPjdlabzE6vx9XwDmDaNLBGbqiVkuleZqywBEjwBM+qyT8iE+BVkKe77a1dnVeJwCsmjc0EY7sW1KaudWzuZLslKHBhhpMmH8DK3MywvmaN4nuwiechn6Ajc66vxxQfUmkniuwczerrlrnbSwcp8+mmk+nEA/vEQL4IC7k21ylP5E73QLGMJ7HWxLGEZRWpZVgjqMEhAR2SyNNF29wxo+fE4wYH+1dt0qYJAHayQIW6t7PwCsPcXmQWET0V+4cNuS/Q1KCc9T26MGRHV6kWRIrcubKuw7PTHibGqPY8Vn0X5KLQBpEQlo01zDcuttXnTt5PC70MR4c4NOKmLV2l6EThM7ECYJDgH4HlKusjiIhBLw04c4MZs5TLeUbKBaiNk4wQo370ac3MZz8LxLq4efGRE5vN2hTUhlnkiQsXwUGUR1eronL3YWsN6q02BnSpeanBQ8ruR4kEoznTYsSATMcYAqE2ouslcfS1EJBdG5d9yLWm66oWf/kD42sKZf9G0j4dzj3ROUUcc487naTcFY6KiqNIrSFhX5tcC9n5z9wiqBxJMIqjAcO8w5EBAuOOveCuRlK7bZrKcS1B8xmmv7vVsXzsz4/yI5rF8tfSY0oYsOc6fceoe9G4dD7U3446+aA//cEQ6yQFZDRnkfB2aSFA=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11.exe /rawdata=ggOWLD7MisCSiYHjtgUexB8jh2LkKviQeSQm17qHFqzklYw8p4Tg7QPVIokmU2FzwOhjn0RRA3IeFMrb5cTmb2kSKeKVVk88uLUT6CTpE4BL5xpB4NHla1CQB8NBoqNFz/T/Zd6h1G8Fh4MwQWPwqjKaacwgUuig4frSnsSVlRJ197eY0ZGHba8aERKPAduamW6jWnDVACAfTuhp/c3n6t3EsjRP6KypKjiuY9qlNnswDYBqgex3oEptHi6O0+j4SNrDxh7DcPTtdDnwrk/JuHrgb3wT5Adwh7b0VdUJrri57MQaV+u7hYShH1gORgOBY8oWPgFCfl3wo9BIjAAx3wBNlBVL7wskWPXLzXnbMAFQ+7/9qF4blYtC1/hxfGTIHbqzMfR4AJ1C8jcK7SAQJY/J1mV0j0XznazVWVbfS56bXyow3OLcQEJpbGhjb2bAXvUtmAO5spuzN4M3aCHNJ0NfNiOcOLOVxPV+3eW1cyb3+jzg+VNaBzw5aszhM6Z4x+mI2rqBeOv/dpNkG7sWNkXKz9cFOw6h5w07c6g1GEQRjv56CDVEDZCwz30E+EQlP9pSWn0Bx1Creg66mnaI0eH657GpoYrgjLvgZxnkM2Kyq+IEXhsX+HZinJQCvvmVUnUXy3P4EWAadN0MHW8vpHzqwi/e5OSvhOQDbhKks5t7Xj9odcHEoIHJsVLQ+3vG74XA6FsPBXB+stlx3slT+9TecxfDKFSWXGpcJeCQconA/KYIfIVyXFF3SKDkKhyv6mSRIFKi2IHvirqf70TuufftQFy1+eiwl+tjONOCuR1fnEQlzaGbxEZDRJYIj2J58HWXRhBFreIWGgGNdsinOcITiWNq/VsclisgGDtSU8YPQqHtw5ZNlautUImIDrekK0tnAeRMHKAIDrblcBPrm08rxjpFTYIyJL6ftJhlLz53CjfNtSZvjUmvW2yshH59TAPGvgyT/vWsJe0PL2JvjAuX07zulb9Gs+QpdwuY7pteGfEMSd2qJRJViMTr/NQ2UxAjBch0kIBCqjfUIRbiKupXe5iIwqAoYx6HJJR9a46DSvSAkp5p4Uc2ok+sBzSqr4VxL8UCI0/XU2BHv3qZ0k2FLYdK9UXT0mCOS7HQpoahzv8K0Esqp1gVTjmqkQ7XYjvm+ciXWdHknIWvO3ZfUwOEAmc7kJY8FyaTFVqkgn5dfGs9gEXL9zaBMxXA7plFLoVNHuCXRHXJmhovG364D/RkffUyZDkI34NByfhYrxoZDqOiIBBQOxC34WvdlLhDtxJSCpSYWfMYFf7zal+xrh+3EfeQQzK5X/MoH7HtSSR59B8bQQhaBM1xknnRpaA8/rzpz4q2TIyo1ih5LrABl7Mb3bC7J5I7vFObOBRLRMxlRbuh5mnV1l9lN55QF/kylvNqr1ufkKi+MFDNmSzoE4dpIQlwoQSqRg93RyuW5Moy01bEfNDkfAOC2K4F0MvIMTaEFKXjaCZX9+FV9RfB9jY1dhA72I1wFgtbJoF2yghtUQbGfUyFfw9nCptg85zzCVDP6Mt8pf6ntxsDuxn3+JVdfhcbBurEbQp9MWtDHzB8FJDZKV41k0Yi8lyJE/snf+bgOZjjrdhWZRDme1YeU7UBsgj8viSf99cYV7Zs438zS/OZKscMi/sBgOa/OGUingrpweDHhgErkNBW7Kv18VtQ5uNJNdhjWgz7kbdpXMGgZlQwSPs7+oDXj+SbUUvtc+sTFrwjEf+yA/SFMNULQjFyvUOmlYYnyAFMK92k8x1FYpJ2ZZTUHJ2U88rBYgQtLxlLtoCDAdNQq0YFZI2D7hdCUWvOvI4q/48lllxn4XBm2RVXQ/ThUaxC/Z8QChUQqZk949QdiYeuLCAdLL+CpBfTj1gZ56B7ojELyNayCwqt1C2tP3CdvOPFlZDgaIvnGJGht106QmCs5B5T6wZfCsfmTgaDc54Xp16vBP8wksq8fI2YduDq9ZgtBLhWBePNTPtRsZFFRpcbSQDcH66KvXPvw5WORmaHOvMI1tx2Eawud6KGKYEWAXLqJFlZUlcd
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2.exe /rawdata=T+6ab+87RKN8zWjT0yOh4WAkpGZkFeVb+0G7emcJuJYPr9gC76doJQSuCNst+60yorG6xj+MZtBjg5wstRrZ8YdhzBiC6F0xB2m+jRuC9BB4o6JTyXNAfccvP/k+M+t5QalWl188AAQ8/WmmUVYeesJQ8JFVO4YOhobYi0EKMU59o0BuJRbtQnBnkN3xvqGknFSmoHBwaxPp+FtPGXTop7lqNwoVzMr7lgzW5Dil3lSrqHVaxe65C2scntq/eLiW2abQxYpviMHGvMouhQlWuYQLtXpU1LnAjDSc/aj6tF8zAzmuj/BUjT4xi8J95DmQixZwx2pKH5c+ZX8cgPvEA0firdrGYJNKgxJmZckRHEl3W3ioIhzQ7Ggu3SntTqxuy8rh0f+V1aFpL7JCqZDVcvW8zg4wMQ5hHbD6fcs2xnJmQfGwS8Xl6CAgVCCvSq5BU7eP2zD8EE1pordtNiOKfIhcvcOeCxg6nnOsxb+6aPPEKPsGmdfCQGRLkBTcJ5qyw4DDoFk35QmNJGAQ0OoZq3MPw06A4RCujzYGGU2y2b5hYJYlPICp7VsMrcUwVvMDAWx6+iRXvCkS6UmCCN9iHYz3LTYZEv+bI19EPo3Wn4QbGuoSK2OeUhArWI2+g+yUbt7U4TrkVwV2K3xE4JOpRFLoGhGoXGU2/2M1PFs/RfMdaDlBtTaNKJ6Irozb0KscjrKPFKUH2Mfh5IjqubckuNz8X1JgenMfR8RXg7yvklHzfa0nallYtPrkN/BAWwb7DVQLK6YbATu+a1ikyvjwMSbyDTNwtJhgfUcU3/3Kb3Ikw3HuxFxEPdmP0YMjywq32p9lg6s7Oqk6ihy1RNGOBA==
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3.exe /rawdata=V4ih1Vin6Ty+xCIm0HOh+D5NnnokLpTmA4PSy4IrckwiuU2kO6OiPQjY0Vcafc/ZkepHdvMxK6k1CRqMdWp7wX/Ndw+5N4iGoEVFmeLU2PxHThmTbr+dk/bioFSgUy4plIk7MUXUUPu3MZdWM/4WGkIBb/4ikwXuUC2SeJ33z/BkasHXTfR93+5yPcmciGFJuxZGMMNOeryz8ckAnEFzKiapsYFbKRzJ0R2VnKM3am/QCOaf6CG6H1qGsLpsvpFfFYrvVc76iUGw6Wf3HbFygoGetPSkDB9/b4LE+y5ml8PUoCNkPAEs2+1RSs/ujW93bCi3lMzYhMEaE3zB+IXCwAP5qQKHG4LR0GJjzRjnxqEnCoQu1O6krmaPvhBrLNln5HtokNAroSuol0Fes6y23zPSh1uNrHPf0bDwp0cYWNHCBXk6oOcQfe2HvSF290eDdFwUchq7YdXCxHibcAcDh0TDMh1vhUxDxEOF4Wqz4Pzw3k2voyCH4IBJ/8fjIp96ZLbrgVG0v9PJVskSFx0/zHp2el/OjqIJNgcZdnFgI8uwsoZR1cAKFb1pRuB2O1/nPWsTwRkwFFTxeY0UFNfgD3pFMbvj9UhRyjFC51jei6vWzAzbcOCe+8ZmQiDOZTzWWQk0WtW109ZEX7DWK/axzwV1DidxEa01abW8GJB3Uti2aoZYX+MpTxDVsrP4Anspd7KWL35LZgbB82clWj4lHd+ETSF9tSfVuID9Nc6XxLswGZKvh2MdkiM1k97Wv8SBBjzQEYR9i+moRhwTkEpB1TJbdOqLAobR5bcvaYbDjenX0P6cFazAUEgWBgQ5XvvzFqUDPYBHytg1hafVJiQTnnLJ7zaG1sn9RvtyTlBazJiuHW3DkkFtSJY9SBaAjVJldBSq6CCBT0qpqiEUMZKjgocbs/gllMrzNtb4KsMr7URh+PvVJXpx7AGgIn0tEPq1uKzCAMQ/qaEFJGn45V+q8Pm7RuVpHezOh0rYxW8sQvkbdepSaTwaaVHgTk50V0/hLUB6behschfy/EzkMVsSLegWomshzNngcKEZzbkqhBdAcsXik1W8cLMa+k/v0Tct96VarcY/oH0muHKZTzyMZIk8pvHFLPLejEVTRaIpIXq4KGe5WrZNU7Z0I3EssVVorEVduBZmQwJqWGayRQ985ZAxfNrGVTHgxsIyr5M9yfeiVfeubvt42EjEYX7y+5/JY+HCAGQNi3JTSopSLZtmilXmvF8ysjKPtkwu1VqV4HHQCVDw4/HpXMAXI/5tr9u9GDORbbG6CB+S/4nNPLG6pMt511ghg2llJ/rz2cXOY8qAcgodWWJzH0MToejcuWREa4xmt9eiqAFpPRrCHBypC0iz6prF65dHBhyQzUDhTuc0XCZTzFe/XxQAKVZ7qhGotGQjujcUK+d9j7j483NQiHL73eeNhvFcg7/7Z1Y8saNxlWj3i0u5TPKxpBq30E818cE5CAfMuF9Zqv4NO2CMMsJkP3DErZSbEF1BUSUwSxDAqGc4yHaimv1FrsBYuEwzI0hyFqImFKvtt52Dhde9vgQvfbrbjf4z6d1kDjmJCIh76dRWTXNQpgiT1LFL9FIqTGaTNcKNLQpGEjRxY0XZAwaV8DND9BNjATSglqrCZvbpuI7WZVGB4OQ5i0s6DZK+cXzTj41gNmMmMkK5ulj+QNOCephHOndN58Rhl5LxepI=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4.exe /rawdata=iFX2Dv/qfuF50oX5Yi7BViMcSvzLr5HP90QcsRmqsNQ+XdqMoAsCJ3TIXss4YvLiiCMu5XJdZesQSy9y7iH4HI42mmkXFSQUEVpg4ICBzW5QS5L7gS5WaaX00DGVhFDUYfmkg0hiTMAOmhmhPysNSKlefQ9UBw0sslQ/nWrySTypxrXv3JMYq6nYsei69Y0qNofnpkiO39v3rgsDk5BX6JPyVh1s9oj8bS/mRK67lyeVixQxZmKhAdoz5p+kGXssHvTKoQvc+b95V8TDsX/geFaxxzG0D0EMiT/1uBIcAI+dfC47Z5SgAaITDdCaZkZQE286GeuCd0UgmoUbklVt2C5Wrj5exOrKSCb0XOC0XrTK6mUnByOyAUSRVts6VHDQpEmHw5mlwv2BUsrmQlNX4gaZ8EoGQfbb9aOaULVwWODaAtPd+Ylw3QzI1HWsh1X6xNNBAhalUnw6kQyJ4CqMQApGSpaUyt/bia+HOTvMzMWlilX2Ph/ArC98qIQ2kJ8nZB7e7QJBg1io6kwsYpVFb4I5uVQodSGFCNNX8ixjkV1Bs9AU+lkShHAblykmyPT9VobGIJ6a5vrQ51sbOou9LxKD7RYxC+f1Z9GJh56gsWDT2AKlSRaLgpNkwXCOtbrsRQf7DoWhlLDdnDKEQy2zuHoZCFMxf6X1drDmkjn8UuRmKS92faok0a054q+Wgt+bGjxkMgZXO9mFtiHiE4c8oJsWKTHPQrEZta67qwX48sU4863Qgpwm6Fa4iAe2ZaWgGMNcT0ud0VC7ymDqF0ya15+lPXadWSNxR3vhx5yQbSgGS9IkyR1ezArqFdXs+gCVKeP5/KeSMYsuWFj6005WwHdEvIe9vmn9v+E6yzvMMXCMdTJRrwVcMVy2yc/p6RelzT2tc4C60S6qGGXgSIGN7L7Q3lnAXSsSkWXI39nUwEKV1DJd3O3mtR9n26BaF9paB73aonb6jMFfpco79WtvfXNFeII3zD417oC3f5mqPc/OdCGzGs9dqKvYu8fKzl5LVkEEIumrmG9s6erXbVr2RH91LFgxgbVy8d6ArBCPxqwhKlFzswFM6VsBoAV2JKQBycDxH6TZ4e3j9U+Un0L5vEyZvDTNQESk8nTJQW3BTbQYJ84+ovlEdcF7vsMCl7bLOvFrGjGEQBeoKdnJ85q36ioxW6U59H2KyqO+IrI8gl5KURj8hROtXS+XR9hN58V2nJqFboEg5kOIbJKRv1i/yvNRUxesFnWEB4vzF2JpAG5b1eaAR0AiC+RPKupLzAlSiD6Fbe8cyYsP7ViOVoVp5uHfsNGlreiE58NikK82V1cHYPS2b6cn4lzybUE5XW0rLCd48qxvhJiqOzmXjDPkiiHeY5MfWEpaiUBdWDhWzwZ3RCyD+pzjCmoMWzNjATmnCC2haVC4r0pl2Mkhr7s7aMnm7pGvK4CXuGSSeg7+WsmLcEvRw5Bcmtv2INRcaW4cYNEZvbKDaqaP4tqVOnlagm2Q6ujv3tG9Wcb8AttwfwXofcIWqK4fDby8WVx/iCqEN7HOfo1fkfIVpqRT6S5GQ1g0FS5DiwmbPnbxTtwO6uCsoD0LmPUGVdVLB9wnr84XKeZl/KJTSdLPPzt258xcdD06ahc4NDiR4rxeLjZKA1FCVLk4Y7ZW1xGMGfJJn7snpl40KW/fpf/ZrPoRtmKsdWSd14N5tYtVew6FV9NRMlE=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.exe /rawdata=MyLdHgOohncsvFdJel3wFeXIwOSgOKKO2FBGtcRptbJsusUlx+mxWpFxgbYBvF9H7XIuK/uKFv2OPTZYo+9/sJdHuevJr9hYqcyNFKWo7u0yo39XvCDFY5P2u133eb9HcM9AmxxB6OT7ZBoMCIhY+4uvpwslgqcDcARsMUfm4D+AtDMhFMEPuIu7kF1Yj8l/mSS3gw7EBdSzgapd422DBgl+IxxK/m00SBwKLfF+uBwmuYKEMV3M2aIdxHeeCNblsyVq+Ru6HuWKUrvl1BpJ0BbkZfkPkjTCZTACxC2gSDrnbA9GiK2joUqUIhE1UIusVLDDTbeCRni5sazdUpgr7Dbuq2mSd7mu1j0GZUPWTK8TTuiv0PPdyLSfHDl2e4nDT/96gyLVSBw7jmVRGGPQGM4kuqhRss5sozjrF38brBawyeuPQk2/SVNK+/X9cUUAOdqIgcP5g2i+7Jpxm9NkILLjiXsMu7Y7lA8PLDeBuYOQ0iqrKw937vEKyhEeBQ6qJjgzVoBXtOy4M5tO3+ySicSkV66cKS7+UDqcnD7VlRtcw6gc8qMcwHt4LfXzfLXVebBIZZvlTPnOr5+7ZIxvqMXvIUjTh5cDywCLPyAYfi+V1SQ0hXaNKDdB3E60hyKAArlyAbLfAbWDLjfIPRvurPhnMVzUeoDzp3C7uZ8liG2z+eQYv3XRTKVHpPBExhrrDjjY/Q+bBUJgLUhiFvfMmqr/kgb5YcQvtwq2lEOsczDQAEczXKA3kJq3wl3Q4qjIx6hefwUTdHUF9CVHXBOWHFwJTK5dVkPq8Hc5JK4IYvyBTHpEoBp5joW0tCuCMtqhqElh2XVk1SP4/XdJZHRD0Qo9Jiu5UxWVinTPqhL0q3xIAkoD3q+i1gC0BOrymagHBCXjX9I5+5IeI/NXKOWdQpox7YpKEgKcL4yGCFFYqL35ySwxFZJNT9FTpnl4opdgO9JshkS7oEGqzYAXc33zrvlboZqFa1c4Z6DUuWlQ2VPHMI1yIF+85Idwhb9+aXZ7
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5_user.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.exe /rawdata=MyLdHgOohncsvFdJel3wFeXIwOSgOKKO2FBGtcRptbJsusUlx+mxWpFxgbYBvF9H7XIuK/uKFv2OPTZYo+9/sJdHuevJr9hYqcyNFKWo7u0yo39XvCDFY5P2u133eb9HcM9AmxxB6OT7ZBoMCIhY+4uvpwslgqcDcARsMUfm4D+AtDMhFMEPuIu7kF1Yj8l/mSS3gw7EBdSzgapd422DBgl+IxxK/m00SBwKLfF+uBwmuYKEMV3M2aIdxHeeCNblsyVq+Ru6HuWKUrvl1BpJ0BbkZfkPkjTCZTACxC2gSDrnbA9GiK2joUqUIhE1UIusVLDDTbeCRni5sazdUpgr7Dbuq2mSd7mu1j0GZUPWTK8TTuiv0PPdyLSfHDl2e4nDT/96gyLVSBw7jmVRGGPQGM4kuqhRss5sozjrF38brBawyeuPQk2/SVNK+/X9cUUAOdqIgcP5g2i+7Jpxm9NkILLjiXsMu7Y7lA8PLDeBuYOQ0iqrKw937vEKyhEeBQ6qJjgzVoBXtOy4M5tO3+ySicSkV66cKS7+UDqcnD7VlRtcw6gc8qMcwHt4LfXzfLXVebBIZZvlTPnOr5+7ZIxvqMXvIUjTh5cDywCLPyAYfi+V1SQ0hXaNKDdB3E60hyKAArlyAbLfAbWDLjfIPRvurPhnMVzUeoDzp3C7uZ8liG2z+eQYv3XRTKVHpPBExhrrDjjY/Q+bBUJgLUhiFvfMmqr/kgb5YcQvtwq2lEOsczDQAEczXKA3kJq3wl3Q4qjIx6hefwUTdHUF9CVHXBOWHFwJTK5dVkPq8Hc5JK4IYvyBTHpEoBp5joW0tCuCMtqhqElh2XVk1SP4/XdJZHRD0Q3XEXiWWGQtz82R0vfmcnKrFNnwfLZIhyByU5u7Y1B9HpZAuOV8kytr9PTFJE1d9jadP47pHEbGzIwzN8Q1SxndhljyVXzY9HeDpUUF2sMXdLHycRpt5R9ieK1D6mEfxvigS1j2K/mQpM80RelaY1Ic1qua7Cc0R3yDLFonaLcH
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6.exe /rawdata=PezbPAEJ6db3Jfbk4roRBkrXICJ3XfThYePZxtRZA0omP2pDSFoDN0vTkBABi/8h5Rfj1xRSowRJ7Q5W04aMHKVyq+z2h9EPZKt4Qq1KRAp4rKuJzLDYNhk00WbSDHDuqfxf4YOr0X9w8/wsP8k7FLU7jvI6m4TNG5ZrxvTE964bay/hF3rWntc2JnqPLp4+mvYd0xFvIvm0hMrr+bVggkkRh82DQ8i/kjzmtdBEGzl3bKN1D1t7GMFMvM3QsYa1x2O5KlKJKqEpShy1MhtodYfVPbJfu53BUGk/cuSzhvENBP8JVOasH9DRkLJ/ThkJrCeLQL7e+BdLi4Dz6O5PMCWxlvqROGyZWeKsCSI1zg51JWL5wi4iIjYpgFUJg/i0qSl+3OuqSUpuaYaPlqvossZuoUGNq84+yTKaqnT3Igt5NDkqY5KWW1evyyu8C3pENIGM2GEh4UW7QKqB2Rz3TlseWG/YaGSJx/M5Loq/tkXaJrJrixCvj6iITRu6AqdGBtFBfs/JgCeGo3L/fQD5Uco3dMQSeracPhBLGXOjTaRDiAtdwyD34MjFmHwDEThDxFzZyBw5Ayr3Xp/eMitcYsFWzVqVGl87jvrMHUhjF5WYnp9zrekckgzYFy+DS44dXjKAQkwy3HGvegKmDck8qWlhRF7NxGkl5nA6MP55GOa1EI8UqkGW7fK6dL2qH5QitmBb51g5GjPeyyIGbaDZkvBGZSjp7f94nhpK8v0ZcgCZ/BeMUbZFN2YTP+15NEuTjYKGy1ZrySUTH7z7r2OAYZmokPFcL/Zk8MmHl1lSEoBx09rhI70fT6U4MxR6IMUBLDfTvUT4yq3EpHnJYwulqgaieO9RPIzwnkVHcKjuRIEvqlXquOHtV3YcN+uHV/7Mp7IRvDSPPRZs21QBceLirXMynOY4F7VNzi2Wz0P5cKOVv1P5xWaS1Qd/abcis6qUqTf84YQJKa6XSI6tA824U3wlYG5Rh/CTj572SUcHeu+TMWs7bnXByeY9JZ3NrDooO1y41uwWCjVm0y1/Pb7Ot6UCCPGsRmtq6Sv7q3r7ka27Mnczk8uc7pm7KskgTjjwUgksTGUYWLC8H8E3b0yZiD6+6V0jmgB+Y4RBIrJe52cXzpi0kw0woaCMQ/gc1Y66jEqJFH8WqVyqE6JG9iNmSApxVAYWoom+/wLfPqQY5lkLth727t6t5LlyvlF0yh82aMipHpAlrR/urwn2KFPzxHcWAaty3QFWu675WXZV1M7gYYvRVR1Mi5lApFTHtxkpNIL0INvFVXn/1sCX4qSUotGyj2R2sOeKeCCt+QMzzIe7f43iRqgy/PnxtcUxeFsxMAXK6UbhSz5if40o290yODzBE+pPP63AUJ5JvGwF7cpYVbEbuGGXBH+hB3F4MXAQGPEjfhIsAuq8mIOwqdec8dayVX2nvuDimRTR5cZTErLnSOrFaLqVIFRGrFHokJi+eygexiI6rbmzQz12jMIZfy+EP3w8M8qOx6iEuBlnjRc6BxQGDm7XdWr5wz+t67EV
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7.exe /rawdata=Nfpbjk+tnMNSV1omXAQZURkwOiJQUEh2lLd5SNUVgE/gXhxKVjOlXcrt6dV5en+D7TMpAi2UN6dQl6qppjOvMyJvFOWpqO9vj/j4qD4Z2VX9UAkOp/l1K4PcEaMdkZGnpM6EBXLvRYV6Oz8+U6zbZNOWg+aQQBvTxwNYTjzhIvF/YRD1IlPDotkczL8CnFTkc3YKp/iDEEa+PZrWaZacDPF6bY3eQt9FMFZUL6341tlKt9Cnl2QnlZqkRlc+UYzi8qoPGEumLbZ5bDGmEvSL50FQAn/NuRXk9YDa0/VKgVRZ9UJKakho/p8ArxGRXrJ9iTV29F6IPp4PRFqjG1AlxrN8AUJOUpHEduOJ823Pz2yPUbBPI+6hidr4MOgxVEx3Tfb/xtjxSLSMmSlLuC8bwZnfzGxdDJrUjUQNnm17PP+0/XFbON87pt2Kyn5/IqS2u7A87QxX3Wva3Q27JFYPautJusn0ODd/vVlM4dfSCp0eEZmVMF56hWafYBTVXIAMes5ibRbDxnswuEZGsHkVZXrb8pWR1oGeSifQJgVguc1J1KCxYz4P0DVdKwg534rSm8TChhni4ghuewLLT3mrDRpUiGFBTVjT8WzyvXLYsrN1EwihIS/cvuZ4+X3IzMMQSPQQuvAmiByf3PuOjLv8c9RJa/5W0YF2eZ+L5L60heSIYvGE7BKykOjKktxtfXXflTxxE+WTCDYhWoBfs+5v7q9UaNuRqg0UkjNJT/A6RKs0cZuAiVXAucNT/qILgz0Ewg1VSV5Ri0e4ZotMg4wKa6VXn2lUwxcyfXtRpFixzHB04qDPN194+QGfkMMLz4CpJ640Y7TqOfMB975CN0Z/nzP0IKtJc6p1PGyzWmn6YwabPbMI26wZQk9ND0xhkkE9AESv0cEJT6yn9PBMaikqQcfDy5zNP1dzONjH18PVoi6Pq7Yt/NxeNNgmDR3t/7yStDaUy9YYrUkFUpqsntJDHYTYJ5YDogcHJtknGulVftyUVzTgBmHAEEqHpfOm/yVCPuYkJnY9xjgHfb7bhdkCJxUjLxDAwonbFnVpjz/yG55zvmtm5vXGe52GqhhESOnMXopFRI/PBhZ+wuVy3lt54GYWLj1hPOIsjil7iOpkNMfgBf+b01PZ/jSFzOeJreKWKCcCGH1+XH34eq6aKuuDVR8NtiXbNhuLBBFuG9XYFosba64HAZFYnWFSE+DO6FInpAlBhHhYhaR730omQnHiIe2bR3aB85OkqPNegtYTFpw5+Mpmx01F9AcBqFeNnUnK+LjQZd6UHOZMpRnZqinOzG411UuVhXWvMv8eCNQkcgYJvblW1vlRYlMnDQ+JWrlIvKVuTMWfVtBtNtPfSm1WAw==
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /rawdata=w4ArLgQmOgpnD/D2uHFgzINH+v+6oak1cOnvyUDJZd6s7GvD+r1wj79VP7hU08QWhkSsSi0ksLlezD9P8NXToB1pCTDtZgTWKuoGcXphwWBwtuubuC0/i/V/JmkDBiwrOCgqS0Znbg8oO8YwgcQlL28Qmg3Fi2TNEUlpMLjzI1EqeNuxk4jtH9OpKvLF5GmVxN0qD5xkejVAb2hVccVLoHVLC+78vaaFDOthru7shKPyoIxCFP7oufspobBuq8Hfgtcucs9uov+uutFpsMH+1QRrVMlJFODkwRNqKPMJUYd/L6oKFoRBOlUnc9TtEHQD1qlut73UpiXqyo79rQT7Y3r7V01jQoUh81WlrxUeTLrO1nhCBXlBnxCDvdV8qN/2dpeejR1BK2URsG23ql7+BURnX2KrQTSgS0XsRh4CinhSC1HhEPfeaAsM7ue7D7f8jCiIzIdeaQ6Rby7ToGLWJQIF5Ec3NC8I5E/54Btac/+mKTFNReugUfDmz9kIgp2mlEUuq9D52nJm8nxWGwwJCQZ1QuC7O/mfgmchGtx/m0/gdYdXjgtdf1Lhuf3FLD9hr0VHEcPxLllQ1hh+h3uo0U/XhJTxL76XtFUVHqj61yvkxqc1EA6yLkOu7Giz9JilbHiNKNFDe/GCZLU2G7jt5nv4BwFivULwqw+bHm4FdQ+zHJP7sHjRiXEWXQliHYB6mT3Yv4nwfvvQahA3kqZLcrsKsndBwTXKZqde6pa0ROrJvQtewLrFUs1U30DytnDCJh16TBORKBylSIUoozIZt6FlrPob8+Gym3rv0LZLoMtu3EOk0YZgcBVh2zxesnMSWBQZeL/rgPX7fltVtYhNnJUUIHmlAidOZd5HS8Ka+PJKEp2tCwO26CPlRkArlLj1Qg3IyCCruiPWRkXw7zmBG0lu9Xw2emZH8N4wWUHXmmWTiSI9h+h3o1vFEjD8JfIsXjr5BZNUxuRyevKMWaCNflFscPVb95ScbBFIeLoDAAog6lvZuxm9EN8bzqS0gZX6ovWwBRG2/pxYzydcufA1F5cCbjhek0o0CaM4TV9rVHoZ3R1hSO0DOjOBu9mh8E9W/ZGB2B9gjIFbz0/humJyiWxeDCQwLyCtbrOqY1Jy2DSgYE9QC5zMS6zSfnQvV4C5jmu4peEZpPFDLgq6BULlAyCTDOWj9C1BhQoKObe2oTFuVzbnLthSoVVQRapAhY5B9/aShXJ7Z7Qi4UGfNNNFmzDE3tyYHTZCuU2ENC0x5ybzojADLfvyfYz7E8jMvRxcuSJvfKGMlN5ryJpc5Dt+/t8l/+Pqrd4+gcuSahGcg0rmgq7EjPg+zdsPC5mVAoDntm/EEv3FsL1Ad79eYiy9Vg==
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-11.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-11.exe /rawdata=arB5N93fQIn4H0LXB5bwJ5z4jdUX1skU5tg9kTmf0vo0VyWaZ1S8Q3UmQ/ZXUi51UBY92xZx5PtikkLu4jSFyr6uppdGiJUwcCIgYj9V1GwoEUK2LYDei/vP/E03Ax80ncCbpQRc1dbY8WmSxXinwO+xgA679vHS1cyDDBfb7S6xPp5LADvcNvu8QXIXQaVkuEydnwgehiDO1bVP8nlluQPhVoFxEsoAfKAjg6RIEYTzOeU37RdeMaZmq1SpO9ZJHiDcbTGPyKWcOpOGC4bA3DxHsvPe5i2JoQOr1bUFUdpaiUtaBbhV/ZXgLgDm1eBALeF/oZ4g9ow5TGGLA1sMapvZmUIQdiveBGDLmaHL3+nu7QLVPsfjafNobkBaS2adgdtpcTk0AAnSPD5GI6OtLPzxCVuhuB8gEjOVBS24tHtyiXVqymsrGKntq3wM/W83Rjs/ROdCZ7EBLvPqLVr08WJjG/EY5TLzZe965+0hpoeVxxcnU+0lQ/3a8fFsu9MMJiL1iNBgBSg9umMEzLVauk8xAHrlhU40XTYckZoKs6vbAlU6LhvZd7yBkYzjQ0R34IppjVXCHiqOZq6Hv3mAkwbd8/uQJ8plt7DrtvgJLxALKfaBEKD91bG1qlxfqK/xRujjtRlh2fCiTl1PT6cjHWyBNF7rZiYkBUkwgdDx6khup4NLlWOiRZgSzZfEfGeyAi4uXI8hzCLm+yJjc4WHw5avU573mpi40AkX7VguXdC5OLU2cki0fpRvk5pXDAc2tFtJwL8YV/acESInpjxfR4fC4KNaFNO7S3PQQs7l82yNkyFlb7ULZ0Q4xHfUsi8GRR3V/ve6Ov3KWXY33ACaRmkEPLdqneUrj4czI/J87a+Hf6zOuaJIqlYApsfhKhXpbwHX2DyH5p8lDwXj8+lLDiifH4MRljwdMXMr/U1lZVWkEXwuukBxImUnPw4zhC3gsa3XmtuNYjC9K3ksFmD8NirjS8ds81EVrlMszgupY5Q7iAb/PLS/Wj7CtSY7m4+NYP+N9CZFr1ws0zeequW1Cr1e/RUM2D8477Mg2VYp62JzHIDIlkHoA5YY5f+C+BNn+Ij5RxOIAf1yc2dQrA5Dosux1roBtgYkck3I9mBtJCzkw4h91INXljpzk8GsnrhjSFR/qTEwagELaRzGqF5gQBpOn6hoYz2M3DT1TQkz7EcZFurOfgeJXdts8bPvwlcbo5YcDqmYW4BDFmc7Hq1QeuJNL/pPhm1wsSG8X7OUp7/syLFa/ElkG71JPVCwUrypAvzol7GpZZhwbuvmCWRdJ5MIih/zYorI7f/K9gZKNzPtVTPOE3PTxwf18D0fqBH0vjQ9Cro0E++MsNBbBXqI7GoliwdF6xzVhIWyWucLyrlAdhZQq/80zPLwMyyHtQTwCWu8aoINWC5dWVvLceU4P6vj3Xkc71JrnUeHdQUX/AYeqgLGZm0+9AA0I86CnuibtXzZK2Vmeshw8GvoDasEP7ONwU0dPgmI0wnjKxhkflD3GpoEjmfqbbxHr6dO5wIpA1krhfZvX4caUvsCoyCXvNAwSzih09e712lwkYzpffVOvWqea0koa/WMvyCesb87eWyw/IyBEeNEe3VtEFZdoU/5nknsZflb4Eh9LC2luMfC1tKIN+Rer6uM7Hqvzn0Ep0ZPiFSbjz1/3qfS1ELwF/kEjPHacXgknARaW4HHs7uHWzNLSrL9sHyIohR22I7q4P5KngkpA3HZzKx7+Ae9EcjUSJuX+iTiPjZ0TKdvwtdMBptIjAiUDiFTDLdAQtG+awPnoYMQd3MuyafChOOyp85D9zzXdcbAh01XyoxN7bug2dOA1p2BYzhXV4GuOfiGBC6yZqvH61i6HSllu542ZiMWl+LuXswvOC1j8w62aIoXT1sr4sAF56bAaxiAprzuhZS704KXwMYfhfxkuacdNGJ8DCuaBr8Wy24qgiE0dAOV8EdB8ixPOt7a1CPZ9/cEjFdSr7x/sjD1GMJ7xqNLWazea2++IFfDvxjqRBP/L8GwvUGF43nFLPgLlLl0FrmU
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-2.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-2.exe /rawdata=EiSlIwKGwVfKqsWfMhurXhIFQSGsAauFYFVRzOmnJ6XKBYQbSZaAIJcHid+STRXHSFcMGj0ftIIaxrOH3gAfGGapcSJqK1zGnKxyitq2ozJHVe1QYYy3DMmmbEc7JfjQQ7A+yIaPOUCuzGbO2Mc4dQthgrTGkFGHOBGX6IiTd/M4C8UAWTQveV2NUb8X/KSq4dgumCTfgmWEe0hwEwfp68qUNarTG9BFH00v9QuT78ncaFTBn4InZKd7jRPTXAGzGnDnU8hHHcBCZbbv22QnNQhHKpoBACTL8ciHfnZTEPG9ttji6x0mPLZ1Bpvqm2XLVYC75nkmuF0ojpBKjw/3RME8GWGJjbvrvvyrdsNrqzLze2r1G0luuqZatv1ORuNBLlC2KcT7vj4dbWgNjiYVeBxKC4PoYoWo+FqjRkeAiBpKudwkG9xoNPOS1H69m2uO3SNoaAfbauqhmhkUOJ/AMuZXiR9NlbfdBpx0o7EsZ6vVq26yhsp9wOwVpFxIIG9Ti9pup3dOJvZybcIj63CYURY9Ebn3rugoI5xHlE6//XEffDl8vZiJbMtx6LCgDdRoFjbJ/ENC9NRu5mIic/K0vckOjGhPg16ySH72aBoWG2CEP0lzCENYcR8pSnQGQbWY+snyuFUkhAvns3uHEJ3gy8QEm55qo/4RwJyz2ndCTRi59JrWYmzlyZNRyHxSRKsE1nrR5IO1qH7NqCeP2OkrZ1C1vrY1f4pb1fflBi3StjF7oOX1dZp2g12MN7ErbC6bV/5wm6DRRiXXYZmO+tXAc0UUGnmfJmNBK6kHZ/rHRnwGvIxAGVkrOxSFyJtNVsrgWN0lc3IecGASODxT/8+oAhxszqm13Y7gWoYx1t1KkeiSqm7tjCcDiYJmoigzefmYfE0kp8HqEIX2SKU082PEJ6RplPo9ycoeMMoQgNh/tHs7Hco7Tf0rcydDbrv0mGCzH0CyriwMA9W+s3VyoMV7aqFvk/UcgvsnFCaSKgvfZLCkSXhrtf//zwnbv671BAIU
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-4.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-4.exe /rawdata=WcywhtTOze2ok1T3BBqc5HqvRhx33/qMjkG81gkgRjFdr4Ez/inFS7cGa1pFCfxirPRhaGr11SVahCFemgJov1jR9kDEu2GKc1Fd60YA2gIquYZB5yLF1I8fLZPozBodZ+yG198j5F/b1Vpj9qCV4CktwidlsUQMghVSvSqjI/ExqRWnVnbpkD4TS0zd4N/iJcvnjrA5auqPxoyCIordc49Y9Lo4VhQIM/n8VaCKJ2EcsBKn5hsJ3qS22bA5823C5J6Cqgm1NOPsDut9wqURH8djGA2Z7NC+ZuRuHjsV3EhI3lUh4uWTLUSyxmTHE5AOkO19DukGbXwqN6T8wUFTG0ppw66hV5GRz/jzHBP9np90PsGnuj08WWK4eUqexzCKsmA2E9mPHzmNGg3ixOJuLuJUT9sanTZZkkmI5QkqdisNwZf5NwMtQDZALVSyE/8SAEGQ341HDCSwsXx407q7/3ReGsVZKvabuvw05jTPxqiGHVk2O1DNQID6OzjoeDDOwRDi1qh9pVRMXrWzjRJ4WyE8GQImOF/Lotu6XhzuY9I78fWwSEbdX3LQR7kd+e/EssnN4i7yNun/Ip+RSMFo2DwKtZNtt8gp0vSPXv7lXFUv8df3t8dMObH/CTIkxDF4vTVLjfkoIM/r7SaN7G8gcMym/1vsyD9C87xe1il5Gakcqls4QhjeSnAgza8HJkulns1NVjnzKaD1DGQ2pbrWU7ekameGSM3WlIzD52UEhxAefMbBxw8a3SH2JVxyzODt8AOcF2+V/byXpOf/wUhyfYOz9oC6iIcmN05fdBWbiKvrVarXrVUZpTDoMYeaELtqu7jD9lXmg5chP3Caz44NTW2cyv2b4+4pwqkUclCwDyFCqJIVVveStiAB2QeNSneWZYsNbJ92IGLe0r2+h1qI1lnUe+/E5gt5NXGSXe4gUNk90m9I7NXhRE5tDVqLPHn5HgBNvrgKy1VGG366kwgLo8Cg95P4Wm6RU9qwLrXlkalhDJwJP2LOQZoBlE1glbDxuB4/+b9LKo51H8MmM3/LvxV5M7hXrUZES/cQhnhx1uLUKnIlhDlwc6ASHFcoKUdyS2kLKvPRIM4AuiLIGef5L29UAXtgEkWzvEQ3kcuacylumCcrg1vezvoTc0GzBkEGbE7j9OBvS3RuOLfEye0MUJSCAX20o5Ml+zdhl7EhodcDADWTnYl3JKqFoOjndWEpLqT2Hi6BtbF3L+EQu3aMHTskX5QzsWwlvMgI3vxObWaPvsXP6itcvUh6jJSMC2k7/uz6RZPjHhBffHyNAochP4oTdMi2LoYkCwE59vPrepXLfrj9M2jNQcJadAEa5JSgifLMsX8oxhRyC1BajdJEhis/xmRPDvE7U+pq1KvU+wJ66lAxkcGeFaMpPlVwwIMyCOtGyHn2KO+HDhe+Gb5+spnAZ3Oaeyjvqi53CIHXKXUmM2CioWj2/D/hlwbqvr6IVO/guS5PowpJfzqPCVGbtHTPHbeRp8te3yHrv+6E4ztgUSpYzrc8nLtNdIjEIpgdcTjaTW2RxeYOVCtf1SUBfxFfFxpi0MrM4WaVDT5SVI9gJKs4FWtj8576E+MxjLtsUAaheG9Q8y4+P90E9dbHmATL4kFIlRykKrsCirs1Hcl+QDPEg1LNqZulFkKlXxoWspY6yEfQtLLerr6z2Ixoc+QKHa2Yp3b2teSZPULmnKY=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.exe /rawdata=ogOyypMYpzAPkIRlp6Y5kQrLcxUO0bmZM7J+W6yzkWN44oxOafB6gEicAunL4k/S+8sRegIM57yp2b+ql+DPSzuPZD7zSAqUltFjjySzuDppRg6cZL5Yqrgxs44YIiGwog1JI7SAsSkgdnYQ5CbGb+33GooBVLQ7uoEo96CTc2ugho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spX8VtPCogkzN1FL+kBGQ0F61VhPZkUQO76hv0/h2oJd5/GJRCHU1kxzyelI9PA1Ou4qPSPRoLngD5ppn9ifHZHZcl6DQKOlgJpADk2UjBtB4PKfyQGj/9exw23eDiKnj8l7Q+Qi03DSTPHMWzPKkVAsVRlnP1eZaaKvbfhDP/+d0ipiAJxU+rXEzoOQmAhhUtzt3JYkYesZ5sdZdcFFBOS/2kw14d1sfsLuCblfnFSCvXqK0luWaTpQId4qYqYMSEXAN9Tt0/ciQEJah9jPFLsUO00Kwhmor9XbZBCcLFDpHUu53lCn5TBTNEVfxPS8SyI2zhJajRqY+VLIrf22qxJ2ZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBhKSSJX9sKO0ZC7f2bUGFChYXmaJuYq4aXxB/eWwbhQwERU07FrgR/C+f76+kz6XahEF1VCiaEH/UmXD/C1Ptv+So7K/fLHm8F4na3A0SX+s/xQfAbGGr8h6/5qsAw6YKwbfoodC6aVKm9Ri49UsxN6f2p0XoOq7Ybf3wzOW4biY=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5_user.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.exe /rawdata=ogOyypMYpzAPkIRlp6Y5kQrLcxUO0bmZM7J+W6yzkWN44oxOafB6gEicAunL4k/S+8sRegIM57yp2b+ql+DPSzuPZD7zSAqUltFjjySzuDppRg6cZL5Yqrgxs44YIiGwog1JI7SAsSkgdnYQ5CbGb+33GooBVLQ7uoEo96CTc2ugho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spX8VtPCogkzN1FL+kBGQ0F61VhPZkUQO76hv0/h2oJd5/GJRCHU1kxzyelI9PA1Ou4qPSPRoLngD5ppn9ifHZHZcl6DQKOlgJpADk2UjBtB4PKfyQGj/9exw23eDiKnj8l7Q+Qi03DSTPHMWzPKkVAsVRlnP1eZaaKvbfhDP/+d0ipiAJxU+rXEzoOQmAhhUtzt3JYkYesZ5sdZdcFFBOS/2kw14d1sfsLuCblfnFSCvXqK0luWaTpQId4qYqYMSEXAN9Tt0/ciQEJah9jPFLsUO00Kwhmor9XbZBCcLFDpHUu53lCn5TBTNEVfxPS8SyI2zhJajRqY+VLIrf22qxJ2ZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBZ63JyCHxp7uqti/1N+3Zc49+hGDS7xgdqcSa88eAc5FAyFAAzey/5QUMBLnNnFPZA52rWgnwWQkzuGfX+u4dGX8GkJxqxvOn5f1G+sj6HAiUqNxn+SKzUmX25uFGB83K4UMpaMZdw3tEHTlUE5mE4q+2LImMIxSl6eo4wYj+8kI=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-6.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-6.exe /rawdata=G4RJp8Z9LGlF7IY8hhCXt/+ZpS9Tha+/Mwgzj9k8KjU/oaK16lUseWcFRmEY0tD0gjCcAG9I2QL7niRhI/BXvWaDQ4q+qkuIOyigTM0QhYJZqRuTykHzAW4nCEpeaXFJWE8oIhduXK1llPll4wMd3ynf0m48NNsu47OSM4npkIguYvsd6PtpzrDqDQAqMQq9MUasuD6ydJk/1cF1pKtZ1i7rhrZuvXw+CJRQNRvD6IEGvXEbczBUlnzrMr5xeXuyMMaQyOsLOoFGlUreUocOu1OTSv3Y8xuJj0G9vCD3KnYVYh2Qa3Segq+4Zd96Ekvjgdpqck3PHc0dYcbhbEdNL2yBOmccec3T7IpS8L+yco5JZQMicreu2cJeAh8ngM+75341PsYTmkD9gY7gowEzvWA/IrQgydjmv+lr3/cjRWfci+op2gDXkQc+yN1sfS4V+yuNEsLSEwp0LWYALAxVRQVvcp86LSaNnIqUFN5vm+Ofo62ir9VPAVzuGfE/gBOPUOr3Rpa2TH2ZT4eRDFFK+H7MrP/Qf0btPs7g3NpMUwI9gHl6ZrblHI39V0178nSE/jwnfeGOlXasuOGlwKAjihL8403zhJG86TgdMYQHGXv891tRnQS/qPJEuAFjLD7EGQywNH/6WGgm9L1qSiytT1xoViv7xiKSO0maJVJbDe8CrNMrwzoXrPJbHltYGs6+AACR55CJ8ISe9w2a9nmvboJWcirrvtky+BrpS4GtoCjEssET9Sc/aaJuidME81Kiy4BEuZSjnRP1hEFVYQtjbf0ij3VWYodOLzSIkMOwkZ1AhtlBurMywSgy22hXNH+VFM8+VwgzTRs+qfXfQ2q238YCbuWka4xurc+0nLs9ohFvebxVIfA8hQv+tIASxS8t+/glS9dwbbfECZgfSkoc2NKsmMTypMq4l9eH2wjPdhIhfHkZHiR1R/77C6YXf61ZBQR6oFHz5kd9t7t728BZLO+UlG7/UGO314hvdMDLfCd0H6r9p4Ildo5cGco2/reBtNWDrGsA68rqCxXOkIoq6O4k40gcoJM0Dc3YYgqHrbyAfe5u2mP06tlN5DeOM/xjGUOmTfQRd5JgKCmpNaYMXVIB39NaLLbFPwDOzKcqcvRgsZJ3PlRkDCaLCq7c06n1ujWcbE8ryDICpuzCyTibB0J/7pPcww3nm/ZppnshJg5URN7v74OxcDm0fMe9l2BMrtJI93+KtlqQRK9uwc0PzQDnLl3a9r6tuqJOPQZCDI+E6+bQTkESYpJHFRSruNwxIxwxFnRRlYEGSM/igMc1qDmJW5qwoSpg6x0kC5Il/nAHg5uVBuLgpj9t1+oF+lGm/KAOWuV9R9ZdgxV+LhFacxMdO5jJPLV/1mZbzFEqa62mbWMvmbODNw9HJ6xYl3vZfXYbWftgHR+yejziho0axGkKgvpUlOqNFc0x0goJCmqh0MwiY2VE2huS9Nbd3sSV/S6AB/lfdZkJIoLQK/CFUOj5F2isylIm/0/KDIBF547yY/9oLbGYNvl+TGwKf+CcxN9OAwBq6B7NBucgo27nrQuy7WBdx9jfp4705/4kuAdechpfRTlOaR6/08q7e2hzyc7ct4YuJZETFLRkG2O4skZi/WNFbNDVkn4zkTiDVe7aFoWPFLF/vX3Tmj93vZoAQ+g7fF5ofk27sBZhCzVSXx+i3I5rp6G6I0RjhTP/luA=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-7.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-7.exe /rawdata=kmHNAC4sIlTb6n819Pct8iDk39691gp3fePgJtLAj8sT3O13SagOejQoyoZiwcJrk+SFyvAIkg/9ia7HrR2gzBufUi1Ihjm+dPMVuW5dU3nqCMvt4ib0ktJH51+cbjsHLuLlNjbkarpMWHVfS9pW/7n68W8IfAWVYXF9stiQJhtIWaHfT5Mqq79D0CtmC57QhQdhKibbV9LdU0xahg9Hz6/LfAxeDpJ01zgW5xp9+xpT8uC9cBsYSMLskyk3XwmAmKB9J8f34TDWAyRmKZCZnCnQGePkoWTVzcKtnSf3zn4m+n+AciO/jdwiv91mGARilVpRyA2HfCFMtNdyZAaz30fmdJDIqxrw6R9zcec9cTEX3k9HoDPJ2PNmNRtZAxJZPJ0T2zB7bCvBmao73wOzrH/9kX2lbSpU3ZLT0L/O/yDVc9sW8D9650V7lqtHBd2DO8knCLnSw9aID/0ef46SkL12pX4i1orzmtf3Ng/hLXRfER7Jt+kgNFJKdvK+3CitQp5b8vQUkbIZHgfnm+cSogb6GO+Eyy1u3xVBD1Zpm414PUArZ0zjk/2r49GzWnVurszpt3e4/xLsivgpfQ7/r92QD0Fv6/3WAl1v3CBs047/2MTHW43Ddf8JlkE8TmILDDDHt6NJmDpLGOMpyTt7OTixOkG60FpRjUjlCfhiqfwxZq3KkLkkJAjujCeeqElFyvK4GdypwGMxWFyrK+iLA1DKjALp9bHc2VnJd2fq7+MqMWXMa8qZM788hI/lJU+vGtjyHXdLcqskHjlGeBV/4QHeh7yDvN7HaWHEl3BASZgfgilteRbTl9GT+Y9kLvypbK1k/wxj+sTWM7+pe8GetHatIYW5CemnMIdJYve1IvsanQ2pEknlG8nC1PWBMeiovw6OU2Z/eFOCiQ5l4tIhvE1ypekv1MeDz8D87cnAUwQomzStmFlLghn0/c2mySMmZNcms2xdJZ/onXVOmB47tdp3sknnZJRYcMLWj8mkUOmNcGCn7GtwPqqOFjxWSnfTcNOsuvrElRdsdwvSsfAtiJm/43uVq9wBOLnae+3q6XW9G8FuDPd9jc5bxP1McRBKNogGOZEAczHDsDeqSpCgjxoyYpMTbE1mzA1mYwPD3k9EvNlpJ0ZHWW0BVwkpnspIkkdS/k1xRtyBqyhlvWKffAwvxJri5FaB3XaXNJ35jfGp2vrm5ZHtHsc1RfT4dy4/JTX5Ys+mjHPZ7shqfRnCAV3rp1HgAVlQL1ooSHGlJoi4C1+IVgrkvG9ibl5kJnYAJjrnrtz8QfK+AY1qdz9v+pUB7y8X3byRXbEb/YsIchRfvrOUBxHRCUXBw7Wd2xrUVcUgRnFjmKT1APGa6/oHaTZ36hQCu2+e0pMJ1vU54n4icy3ePAtQmBcCdMb2wBZS6HDUWw0fh5Lil1t46rEr6MnyLiGKF2osIezym8wUPgk1qYIbW+B7wuiPd8mqQWYecPepNrxEvjCjZV3V2RP6CZxHQ5Js+ABGU1e8LjFiaexMLS4tqGz8v0xiG9AANSJ8CzpyBP3WadDxhrawhRbvpotnP1lA5bFAoyx98UC9anERrwlI1P5SvFhxWvQVMCy5ZvamKIGsEMWH8jclM2Ww7wjx9SfDlCi2mOxaz34LmcnqiUViHHY2dZ7dh81irsF5wEZ1Q6hu3SAmBBZ7KttWlc4ztb+Acxfa9r40XKlFMHo=
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\KEAYWJIF.job - C:\Users\Jel�nkovi\AppData\Roaming\KEAYWJIF.exe /infocmdline=bDbRLKsyRUJ0Ord5FvY7c2rEIa57QvfRk8grogpxIO+qeeAQvA0PnFu9bGtnYYLuzX1gx8An1xGwycpIGOmuG1sh9NKF2zAaV/rSZsbVSvoJAXAHJ372iie/UuKe4u5Fz/OlfXNbIyQQ2M1sQ4QpEbR4MSt7p0gP5Rg/Kh988Gq3TxdZREo7T9bHiMm4pN7Vvvc452dcNJW0pcOONJQtYBU7vK5sKl5BxXuk7Y62uzFvFPdGysh6d8IDj7FCGaMHLqOWN29rtVhOlLDs43nQIpwglCVjr+PUP8JgeVf1J9pp/vzpFygVFx/vACWrmM+mMklFh4wUAZdeZ+vlnwCidgw6HdXUEzqpvEFinmzhLTVoAMyDbYa9ittbS7fGdH7xyJKCsr8hoYbvxoLSYNu1kgi8M8FkyHMsYqjMvkVbU9ZQWVO0l324DdfaqSZtkFvi9i9/vY3zoTrUOoq1+DXa5dgXCWSAz9sUfq41YNM9lzRMiuokW/rnc0zamL7rFldGsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\QWMS.job - C:\Users\Jel�nkovi\AppData\Roaming\QWMS.exe /infocmdline=qJH3rHn13PRo7FJKjZ3YMJQp+xefapZst19IGRvZ/o+H0P3pZV3Z9vyytf16TPTf4iAXY+bC6kifD7uRWII4I+i//K4MmAvUElTTpC/0aZf2QpO0dXV1rEeKtv8ZWlE2XJwT5ks8QLCB1+B1lVCxT6Zi7kOOP67YHSWoAYcTqO4St96aHlhgHahLKYNCaw8e1FyvAu+vwT5XaQ0W3cIFv7AKYtFDk04ww9Dpb7eaCBJGcP5Qxh7nB0JpzsQuXLXadhbnZhAkLsM9UMXw9Jr7Bov326vpsceWwp/YHmiLvKX9giB59lZS9n8NM4hC4nJAk0VOuXNVb4EeAAououumjZ3JkQFZupM1K7jsLRry65uBieSrU3jow+9pWVApF3TFwyt34wAcBb0xWLMjSLpKf07tat/UGlFO7aB1lIv1GNqobdQ4Fcrnm5XNnlaFO4IIWkY+mzoHDRkHoiczInUTTR/2YxUHpsukzS6495cOyb8f4es3WifLpCdJZokh/lfk
C:\Windows\tasks\SpeedUpMyPC Maintenance.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -m
C:\Windows\tasks\SpeedUpMyPC Startup.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
C:\Windows\tasks\YJVIWV.job - C:\Users\Jel�nkovi\AppData\Roaming\YJVIWV.exe /infocmdline=TQKuoSRc0EA6abS0HXeKvOW9hmJb/fpyEVl3nm4IcoCD78pVTKHX4w+OWX+Hvbn5yN59BQ5gnwtLaQA3aAw+UizANBlg+YbtTFbVFR4bYjjKdEjqbS/QPfKcrRIOUf03MG4xUfWM0P89wJo+qjBgh84xMIz53iZk/nlM3GhVByQ/5/dKLBQLcXbEQb38PFTJXUs1jNiPv3/Hc1S5M1BTj6mweKi/7W5fMU+cv9E3DZYfBQkPGvM9HqKEsg2PQvSxJkvc1V18/FaZKZ8soNRXKNx6GD0yltHwELE51vLslYgawyFHt40DfXlaCJw5PXoKL/7VThCQrLZv1Sw+/TTdSG3Tr55BqmYaV/Fa6Azu/KTx1VKYcGrzmciTQIbga3s5rPWjhGOWoCsfRUuDcCwjydtnv0R2fANygSRzvOJ5+ojALA3RP1WIZs/DyngdpiicFnvZ5HGPZAO62TnIqx3W0p74t/hXKGvZ0yxtCzGJwTLdUL6CQ9L2CPGfp42kDGKT
=========Mozilla firefox=========
ProfilePath - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.55.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\extensions\
ROUAILDE73397174@UXGZI17268980.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\searchplugins\
bingp.xml
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191115}]
Senses - C:\Program Files (x86)\Senses\Senses-bho.dll [2014-09-25 621976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611511123}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2014-09-27 587168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-15 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-17 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper.dll [2014-06-15 434024]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-15 4085896]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-12-06 389120]
"FixMyRegistry"=C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [2014-05-26 1886840]
"Akamai NetSession Interface"=C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe [2014-04-17 4672920]
"Game Fire"=C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [2011-12-02 44032]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"cz.seznam.software.autoupdate"=C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"GoobzoYouTubeAccelerator"=C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2014-09-25 2227048]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-27 18:33:37 ----D---- C:\Program Files (x86)\trend micro
2014-09-27 18:33:36 ----D---- C:\rsit
2014-09-25 16:53:05 ----D---- C:\sh4ldr
2014-09-25 16:52:32 ----A---- C:\Users\Jelínkovi\AppData\Roaming\AIHGXB.exe
2014-09-25 16:52:22 ----D---- C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2014-09-25 16:51:38 ----A---- C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF.exe
2014-09-25 16:51:27 ----D---- C:\Program Files (x86)\Senses
2014-09-25 16:41:06 ----D---- C:\ProgramData\YTAHelper
2014-09-25 16:41:04 ----D---- C:\Program Files (x86)\YTAHelper
2014-09-25 16:40:33 ----D---- C:\Program Files (x86)\YouTube Accelerator
2014-09-25 16:39:26 ----D---- C:\Users\Jelínkovi\AppData\Roaming\istartsurf
2014-09-25 13:05:52 ----D---- C:\Program Files (x86)\Enigma Software Group
2014-09-25 13:03:56 ----D---- C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-25 07:13:35 ----A---- C:\autoexec.bat
2014-09-25 07:11:49 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2014-09-24 06:57:29 ----A---- C:\Windows\SysWOW64\tzres.dll
2014-09-17 19:40:33 ----A---- C:\Windows\SysWOW64\tasks.dll
2014-09-17 13:04:28 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Ubisoft
2014-09-17 13:04:28 ----D---- C:\ProgramData\Ubisoft
2014-09-16 19:40:33 ----D---- C:\Program Files (x86)\GetPrivate
2014-09-16 19:40:29 ----D---- C:\Users\Jelínkovi\AppData\Roaming\GetPrivate
2014-09-16 19:39:31 ----A---- C:\Users\Jelínkovi\AppData\Roaming\YJVIWV.exe
2014-09-16 19:38:57 ----A---- C:\Users\Jelínkovi\AppData\Roaming\QWMS.exe
2014-09-16 19:38:35 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-16 19:38:31 ----D---- C:\Program Files (x86)\HD01-V2.1V16.09
2014-09-15 16:26:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-15 16:26:36 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-09-15 13:18:27 ----D---- C:\ProgramData\Firefly Studios
2014-09-15 07:46:51 ----D---- C:\Program Files (x86)\LeeGT-Games
2014-09-15 07:43:17 ----D---- C:\Program Files (x86)\ISLAND TRIBE 2
2014-09-15 07:16:39 ----D---- C:\hry
2014-09-11 18:25:59 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-09-11 18:25:57 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 18:25:53 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 18:25:53 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 18:25:52 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 18:25:52 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 18:25:51 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 18:25:48 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-09-11 18:25:47 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-09-11 18:25:46 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-09-11 18:25:46 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-09-11 18:25:44 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-09-11 18:25:43 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-09-11 18:22:15 ----A---- C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 06:40:43 ----A---- C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 06:40:15 ----A---- C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 06:39:54 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-09-11 06:39:53 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-09-11 06:39:53 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-09-10 14:24:12 ----D---- C:\Program Files (x86)\Universal Interactive
2014-09-09 15:55:50 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Tibia
2014-09-09 15:54:17 ----D---- C:\Program Files (x86)\Tibia
2014-09-08 16:11:18 ----D---- C:\Users\Jelínkovi\AppData\Roaming\PlayFirst
2014-09-08 16:11:18 ----D---- C:\ProgramData\PlayFirst
2014-09-08 16:10:59 ----D---- C:\Wandering-Willows
2014-09-08 07:17:16 ----D---- C:\Users\Jelínkovi\AppData\Roaming\vlc
2014-09-08 07:16:45 ----D---- C:\Program Files (x86)\VideoLAN
2014-09-03 11:59:23 ----D---- C:\Program Files (x86)\bitComposer Games
2014-09-03 06:02:37 ----D---- C:\CFLog
2014-09-03 05:50:32 ----D---- C:\SG Interactive
2014-08-28 10:06:00 ----D---- C:\Program Files (x86)\Game_Maker8
2014-08-28 08:40:59 ----A---- C:\Windows\SysWOW64\gdi32.dll
======List of files/folders modified in the last 1 month======
2014-09-27 18:33:39 ----D---- C:\Windows\Temp
2014-09-27 18:33:37 ----RD---- C:\Program Files (x86)
2014-09-27 18:31:02 ----D---- C:\Windows\Tasks
2014-09-27 18:30:59 ----D---- C:\Program Files (x86)\iWebar
2014-09-27 18:30:25 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Mumble
2014-09-27 18:07:54 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz
2014-09-25 16:53:16 ----SHD---- C:\Windows\Installer
2014-09-25 16:52:22 ----D---- C:\Windows
2014-09-25 16:50:14 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Skype
2014-09-25 16:44:29 ----SHD---- C:\System Volume Information
2014-09-25 16:41:06 ----HD---- C:\ProgramData
2014-09-25 16:40:38 ----D---- C:\Windows\Prefetch
2014-09-25 16:40:35 ----D---- C:\Windows\SysWOW64
2014-09-25 16:36:55 ----SD---- C:\Users\Jelínkovi\AppData\Roaming\Microsoft
2014-09-25 08:06:29 ----D---- C:\Windows\rescache
2014-09-25 07:12:48 ----D---- C:\Program Files
2014-09-25 07:11:49 ----D---- C:\Program Files (x86)\Common Files
2014-09-24 19:11:31 ----D---- C:\Windows\winsxs
2014-09-24 19:11:24 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-09-23 17:32:09 ----D---- C:\Program Files (x86)\Guild Wars 2
2014-09-23 17:01:32 ----D---- C:\Program Files (x86)\Steam
2014-09-20 18:40:25 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Guild Wars 2
2014-09-18 17:59:07 ----D---- C:\ProgramData\Skype
2014-09-17 13:02:22 ----RSD---- C:\Windows\assembly
2014-09-17 12:52:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\WinRAR
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\Mount&Blade
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-09-12 07:13:39 ----D---- C:\Windows\Microsoft.NET
2014-09-11 18:31:45 ----D---- C:\Windows\SysWOW64\en-US
2014-09-11 18:31:44 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 18:24:35 ----A---- C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-10 18:49:36 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 14:15:27 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2014-09-10 14:15:09 ----D---- C:\Users\Jelínkovi\AppData\Roaming\DAEMON Tools Lite
2014-09-07 11:18:48 ----D---- C:\Windows\SysWOW64\drivers
2014-09-07 11:01:39 ----D---- C:\Program Files (x86)\Common Files\Steam
2014-08-28 11:23:42 ----D---- C:\Windows\LiveKernelReports
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\SysWOW64\drivers\aswRvrt.sys []
R0 aswVmm;avast! VM Monitor; C:\Windows\SysWOW64\drivers\aswVmm.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys []
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys []
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys []
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R3 3xHybr64;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybr64.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys []
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys []
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 X6va026;X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 []
S3 X6va027;X6va027; \??\C:\Windows\SysWOW64\Drivers\X6va027 []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-15 50344]
R2 YouTubeAcceleratorService;YouTubeAcceleratorService; C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe [2014-09-25 1510248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-27 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-04 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-27 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-04 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2014-05-15 3191392]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
syn něco nainstaloval ana počítač, a avast pořád hází výstarahy. Prosím o kontrolu logu děkuji.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Jelínkovi at 2014-09-27 18:33:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 736 GB (77%) free of 954 GB
Total RAM: 2047 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:33:43, on 27.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe
C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Mumble\mumble.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
C:\Users\Jelínkovi\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Jelínkovi.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: cb53b500f3e90131a6091fb939dcadf40061915 - {11111111-1111-1111-1111-110611191115} - C:\Program Files (x86)\Senses\Senses-bho.dll
O2 - BHO: 092950600ea001325d04029365df3cb90063831 - {11111111-1111-1111-1111-110611381131} - (no file)
O2 - BHO: 68671f62832e4803b34065d441f9a2210065123 - {11111111-1111-1111-1111-110611511123} - C:\Program Files (x86)\iWebar\iWebar-bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Game Fire] C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe /START
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\youtube accelerator\ytalsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - GOOBZO - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe
--
End of file - 10256 bytes
======Scheduled tasks folder======
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-1.job - C:\Program Files (x86)\Senses\Senses-codedownloader.exe /rawdata=cC/1FM2SL3eO0MQpuHljhymBzdpoV92KDuyVfrNjtqslGPdW2ykvFVbOs/CMHjAL0kNONPcWSTRtO82NGTnLKWjFHB3/XnybEG7BGKJF9bMug4iucMixqd2Hm0PxF2699UEbIbl06NFEGEl8h7KKfBSPEwcCH+kqGBAf6PArIxyV+IEBB9V07YVVzP/uRFeCAf0+W6wV4o7MZQEPV+AmTaQEhZUvpMXbqHP4dK/TjdFJ5OiB7bTBI/YQrSjHbwT68KcFuIsy1TI9bKrqDoxTsIqaJ+pk+TKU535wnLMXBjLQ+Xpq/hFUgV8pe3HoDq6dZ16qCVZ1UaPDggtiIDH8hrz617XM/DitsOQCJl/AOUb08eGIKPkwhdyrTEn/eSBQ9Ud9vnCWAt9wQYeROlRxEIA0VZoVpdPjsmJ8bWA+H/7FYQgm23TvM/HPuMPaLZuY0y0QSSk6+AfrFBVfajf2Oe2nj7HhU7bAiNwvdguNXTq5ZLGOHu2dEDFx08dSY2FZorACikBIQTpINZIAWefWDj83pjbTzkbt6Yum5R8oRCRCzPSiwLQ9W9SVCiPr+dUT4NN/G6CmjGNs24yUesU0j2tywEGjDLOypZXeywgizRvGL+VDvZoHPzajLdUKciB6PGYSuFVp5V6nMuhg24X0PBNgq7cc3mhfhvRrSxGaPT6zHJP7sHjRiXEWXQliHYB6mT3Yv4nwfvvQahA3kqZLcrsKsndBwTXKZqde6pa0ROrJvQtewLrFUs1U30DytnDCJh16TBORKBylSIUoozIZt6FlrPob8+Gym3rv0LZLoMtu3EOk0YZgcBVh2zxesnMSWBQZeL/rgPX7fltVtYhNnEJyRg2Y1z0EzegG8dDH0S8Sfs5lWYLl+Se/Xcjh+T3XBeSot+i3anjGQfUYBWyTKRW0f/Xqmz5WFlFsV73AE8NOSGWu8WST6f5c2CA66uO2ddJAVr5gKFQfdVSfeaqd2UlrdTkaKcUUSnMXIZQ9WDej4eFuXbf7eQmMnszzP5k3RgmA6/aQ4c2ugnVICer91Vs8wJT4fja3p8WDOLodPfpGWu8PG6FOJGVhWMTtPXn2sePwtFCq92DOsxDDI67AjbxA+448W+3xUsYhU08NnKkUPIWKW7ZL7Mr11De+Rs27qFI1V0t8cacWLN4RYfiQXv7VGh+iEomQ9bQQuqV0/IwZhWGvdst/IdD9su3aKIy3U2/xetm8FdsvIzShr+P94v9HoZvJdQ0f5dIBuuzi2ibfr+KBlm+cz2D2WVwfVfp091dfycGHcQOzWiVgEow4sMolM2aDmtL/EMbyFZt++SS4XY2ZgStTNCP8mzNnQOiy8K4yhpzdE27Uszkr5YCiQg==
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11.exe /rawdata=ii96ZW58RmcHjlnuL/NyavQXK+4Gig0Nz6/6LlyxwSNjDv6gh9SPPgOqbIyLQ63TkNLqbyPL5+yNVC1xsb+EOby0FCxTyWeCQ8IDhj0NUYzBy8eVz36qI/oRL0r2DDGV/yrPzR3j/rPME+ACj/FHrdxvyXNJZAchMtFC1XAKvgy16U1KQAd/uSw5OQ9cf2NlILW0kHJLFimpQ7GIeLUvT1z2V4marEvQ0yKSrU7m2Mkti/Dxz29sZjw8B6HrQvPlyNd3Xlv3PnVWBXUEtKqlb/EEjOYnd+PmvZJNXzbz4ZuCZERTsKkSGYI7O2YHoK24/yG4/JkG8JCJcdQTMJ/R4mFjxUhVitApOWlsDnkg75uevGTtLE/iR5ZLn047OH+Jzic4oObCBU2G1S2WllNBYURaMEtW/cB4I1Mh4em+CQJkzOxhDsAuuNiJtQ3cUsmCXBU0e3CQ5qxi3HcWQNtc3dLwwoc7FBO0CX0Eh6cO5n1qDZl1I4Tw+x/mUYxsSsJqp/9upcFkFBK6HEKzDAFUVPP6a5519TIn4yLy8gC6fj+R3izPn1uewsVtpibLKqW5VWCanR0CSwg4050x8DPV8gSM+BiPPQVUE4lV5RuadJ5m6EuPg80jeDBKPT/B6yB8WIOraon+5/jzOYQYXQ85MDWQHU/JtUh7k/e4IHtWyc2myvUwCDsbpmz5swPRsvNEErfdPd/4bYfxyB466U72ml1rcZC6wS5ZJNyJAHd+xxaUMMcP+z1vKe49rnsMuEV2EbGuv2xHJn3rt7pSif06I3xeHQHYaBSZJonL8IyPhEBXUVgzL+BdqPJgyPMLfyypXnfyAOiGnwY1ySxUISDoTAR69/ewqpuCY51+eJF9E4DkOmmZU2vtOB0fPpaaxaKeqL77fcetyrnkx+qzwyIBHCb3muwKCsJrWWVRkJz/BEaXuVzKkMbSFngQyqEe86FhBm0xs1/roAa60nTIcRzzTLgsAefnUA5NUaTV7gdMM5i3uVM18pfKmjfBs6Cp4ANtc4qAeeQww+W3kY8uHik2xXRC6EyRosiL0Sm+XK57yudRbA2Sbx5JcjU58QQoM93vd5oIMYLpY9sEoL5T/kXC26OJdQG+d9rT4o8rrEyjLBoPqbRgOOaPBfCzpxTj52wXaWSJKqoSJr7CMON5qTUUzbaPIV10wxYr4LcYbDBpRTANEDVxq3zgiSrhwJgSgc7plBXTcZnCSzilYqIYBNUW4JtvmN3dvVIwF/6zzXADhfG0PkmYlQhJYoXV1ZYneBnJH0roN7x2FhIhFyUxs0KL/s6C3D5q3lt8LXmkxgLqRkA+I3twFjXTiOqAr0vC1pimizIhF9Ohpo+Me9gjar34DwquP2W9TVvhM8aP0h8I5oyDiT9rhYpY6ls40Rjb/SRlFbshit7qOWXHmWJtESMiuxbIJBpx+EfTQk2h9u7GGD7kMJGWyxRMDKi9xgeAVKwa7vz8Mt5BHTn/eKeL9WaheIUxfEQFnbcGKpSdgdJh4WNYzpcFVXa2PEbrRVpNUyDWuIGqmobJkKa6TBspSzQrNI7aOCcsWWj8UZhBzH90BtvCnviIKhuYIT3fV1S1WEfEo5RZb4a2jbFInNQnw8GebWB26I+yoTGfQQ+5s6MQuk6sO5FDm6WcJM16RSCxc7FMNGATUq9D60Bw6TC+xeV9TRZFGkApB/frhTAsMs8CkMRFyXT2zSP2SAHLaDJHgsnDp16x12Ykl98mpmghs5NKC0TaoV+1CVtD09VVge5v+Eow0fvM43EEajRqChsyj4s/QSvmNUEU29qlHLmd5NwkdswGciUkumEPOG5l60m6ezP6LXe0TP68P0O+i/tMgY6BDdZRH02+LjeNjMq7jDuwOLiiNg1Ft/ollAyPRafSuxDNscn4Psm9sc9VP8W8ys7XDMKCFrIaG4U4OFtywuxdnV52/Sp2b7hWLrbM9UMiiqQIu6kz0v3nRIM0+CaTtAab3oZRq+/YedZLvVwHucRZhMHIVE9e2zmH0XIwfC+q2kf+Z36XI5LJ70aKnHD/SiByuQyugDuexbNVEopPBylF5hwby7LVV5S6ZL2BAzJM5ztF4DB9ZFSaMQEm13NtL1P8n2EqsmS7270A8Fucy9WvsEHfWG+hYglJnyJy41WbhG0Q6ccqT+90fpE4iFqRjiym7zL5YCIOvPPp5tP748rSOvjCV6jlwWweST/ugpO/YaA=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2.exe /rawdata=jQAV6IpOUbQwfKUudi//YLnCMB+YyiLmvBH4WDXuGZcZx3fBKkfiTzEbH5K3h1d3Ru9y4ApXGMeLnuLdOp+9cpTB98NjqGh13VrpfsPT/hCuBVQecAKRhKFsAhgsPtyCwZ26ZNU42Na4Mm/qjmKNCE1gTittdgZr6ERm/sMxMS04C8UAWTQveV2NUb8X/KSq4dgumCTfgmWEe0hwEwfp68qUNarTG9BFH00v9QuT78ncaFTBn4InZKd7jRPTXAGzGnDnU8hHHcBCZbbv22QnNQhHKpoBACTL8ciHfnZTEPG9ttji6x0mPLZ1Bpvqm2XLVYC75nkmuF0ojpBKjw/3RGcOH0Kd+6r99OSJWik9+lNttpFjjrtW6eLGl/Uj97T0S40RM1ddzOLacocWGIIL276xBsx5x20Rz/JQ0U2NUaO0nbswSRf0IWcc+VoOQQpyfq2JJk7bQ8fEiFx0YuH4vWWOSuJpzWsBftRe9lugENSjEIk6JTWp+8b2Y3J0s0bQMBC9fk42fHcMPFoDN1xbgPIsK2rGLdvWNXgkVKLQmuBNcH3uWzU/nyfIkE6Vx5n4cwxpSOyT2cq906necahREDpEX/2jRkCs3OFlejfcVZjjAgD4fm2b4yXu+oZWzdIjTH6uSLQdcpUHMpBiCK6rANaBXn/aLWE4hmkN6kfjjXst0GGf/D1qDVhnvZJkxYniDWit7+LNH81DIk9ockSY4OVreSsTuA/y1GZv0ghVX+QUeIMmcWnCmVm6bTESSnrkPooInlNKDsbyEuhHP0AGi47CEnH28ShB8D7NhT62dFjDLRwogfTU3kLu7ccUFwJEmgz6v1eApBwDvtTFVQVz9hxszqm13Y7gWoYx1t1KkeiSqm7tjCcDiYJmoigzefmYfE0kp8HqEIX2SKU082PEJ6RplPo9ycoeMMoQgNh/tHs7Hco7Tf0rcydDbrv0mGCzH0CyriwMA9W+s3VyoMV7aqFvk/UcgvsnFCaSKgvfZLCkSXhrtf//zwnbv671BAIU
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3.exe /rawdata=qKkvtzMs7i3IZWi4cLyfiVXpathR2xOn0QRCmLviV/k/c4dtifX9yIBZ4JcvCoQBzcEXer6O03cFQPI+zE2SnI9kj42tUsWCVfGJBJqSr9sgGKf7XscZOLJbCg15sUPLWjiTdPVr5dCToytOl1NB4BIC1wcdm5vGD8FrtxkaM9BE3x0F4kpD/R6VLq3DGRfFH8v+P6dryn0IuJV9CBTFai4uq0eZdhx5FGFtl4lkdm1UwggkvuizkxgMKwKXNIYd+Zx/xPbXy7bP4jwXo6+HQP1JFErfcsuz5ty4sRcquLqpSn3QD/uX9wD6FrTrwKwYz9sGF7IiF77WNCs6gX3yDG5WRQPE4uQqdF/TLTKdBG2kQBwzwqNFSSwmkrecaWCk9/O9/GZ7q3Up65wPJGu+HPY4oAtZKRUM2oHwIptooCj4yr2gkwgAfHGhUYb8dIufcVqxu6G6qTooFjz8Tvl0FXRcv/K2Zt+kGd9Q0nWXs/om1sQSU7wCKoamZMBxFPItYe9SaYIfXjJB36/FMwCZrSBzr48wK0Btwlzw8aAvkq8qfCPgeCOoZ/Ko5adK/VVOj5rgos1Yb/8X0d8zQQ4fJuZvzjC3V5lLmA+1StvbhMBKKBCUCfMhTX17zfm7E/8cPCl4XZXaPAus80JFzlbCyPjGx3PFmwqaCz7rrHDbku8YmAL1iZA+NLP/+bl/Jw9C1o9a9xNyMfVlA8ROS+fKXtwSMDUjHzAlnekvhHRd2i/D6MKBmdMz+wydbzHZ2UpS5Pku4zqOInRdDv3oewgd8RgWUy0jqxCjhxRiOCgbHJexdPY0whty/JG40DsST5iEUYkr2wS9b3ijzl3OnXj/vwfACE82Ky45W9kxLeSp6Yulhs8ZiXnafHlXSv9JRXistfehHTaXCkivq/06RUONSg5cRD6HGcXYijcewX9tcAa5ZD15e3r7tnPcbe9YnH2yWT9vbf/Ym7OX2ULVtxdmVZLOVniVNtBbzkB4IfgDOi5VKtLuWELkDlCBjkgGr9ylSVIqzgszooEm4S0Bnj2tJ/5uUoOjERyXL0/BEsUHHQVUGsTTWPy5EJ3zudU6TRMq1FbpCwCrxNWfgRDNs18WOevI6uFQlB68wiVY9+v34tZjWT3Jw2SKCLJGxO03beVAm2TBcsxlJcAfH6rXhudcjb/8ebj6aPIAHJ8X4/NyxIgy+KiUKFc6Y14FIN5dKl/0fyCAOwgNNwGwbc9HqFjuXq20Epxx5iSfL0QvcJ2Ihzr9NFhslMSxLhSpOPHDLWo8WFIgNUAcNnaVu0kMbmPWti4WMrA5zFjMPTIhKz/c2q4YeacNpcvQvyo4/9uZuE6RNw0hPDsFHd3pkdq8uM1lXQ==
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4.exe /rawdata=d6rTfWHi3Xv/GFuZ9TZWWlgWesE/r3zk4rFLQ4u3V268d9j1+KLX8EUekAJSyOJon9WM8VjNuJXuE1rGitJprGOOHOhbIVliOMKq0A0Nocu4DGiki3qyI47JTGclmq2oon+w3ilTITNA636aHE0CyrX999rqDCRB3xJd6dS/q3yb92uX0oE3NWBB3rtW9h9uTuW4AfnSqMfA1EdnVRPvfIkyWbjIEy+IYSS/kqpsTKxC7pJT43UfimPXmdhA17qWBd1pyWDXGCEE9M1i9OjTDN9JSnOR1RSQ8iHRsuCs1TGYa0AVyFB4qx9RXpspZXCrERAqk/KjhKROf1zwFeERsUxt7N+8XwHo7O+ohrcVrLsbZLPb/OAxAwUJQi9lY5SrJ0PeY5VrQHJp+ULiyTyOABOmjWdBc78672zxh54gJM8PbENwkUFhAexeJCl0nW3uh+qMa9t4zF//79g85RwWQah1tB5qVGhxQDZj0hYXG6+iRon38m4lGgUqk9YyFeo0jladyeFMDHvBEH4gjZCF4QFNrQuwbmYIEkPOSxN5jn2FSu8gtP6BdtxWMyxb+0MCbrKV5/JnAm8sR7TmFp/WLbwre77Qqgk+Flx8I6ad6bPfLYMlhq2kg2Zkeiw8tTH9S8t3DuhUK9UGBm97GAC8OLFcLCFx5bvnT5PZBzDmLzVg59j7oKhcGZSDo8GOpMr76vPbkMtXcO8X8iRh9coJunC0fMTQD8JGp3BCA3I18lXljAfKaTCn3O1eORNmOuziVHHO+BOOvoTZ97yozD5HK6eiJ+AdTAYhHALsluc8riwtdyKcsqiRM1iOVhOXaiqbX6xNDurbjrESDm42l6u3AHYQKwTfieXOA5D9lBFWM6NSLp6we5hDsQMXGVpaEsKfeXAfULdn3h+hvDcC5JsCJdwfwishs8Vm0easBRnrN5YztE1VGi5wR7A9UTdBaITMYiI2XvS4k7ISKh11shyqmbEOXNzIf32tXdN0TQD4OjWSq0NP+1ozzMJF2rTjZJ80FXg0BZSma0PnUbmZiI1xvGNd9dsx1Nb8bNUMe6Y/QCb2bMYXdfqVcInHYcEookpZVvMJF36Q3/7p9C1Av00n5Y66rKcKD1J7p3DFFWXtWvHd9tdQBVigj1hBOlCSrlKCYZhDyq3F0jusOjL5SQLR07WKNWOEP5U7wrQ6kckraipSzWYL54NJyZzwTJCmZvSY6UsiO588LMfm74frpQQmtgBrURrDjn3O40birtLTzEMqf9s+zjZTzm6Y1w7CNgXy08FkJLUg7H2RKDEPCqIPAt7PIFxDcvxVE6tjv3xza54/QgwGA/OT8Aic4WUbj2FKD4UMFvgKZMoxVTN1i/YnOZwfvNqQy9/dhgSZ5iJqvkHGrQjETdtjG4UdlFNLo2ycwapVKaq35zLruvyIuGxU5edAI5KUrXewW6j65dl90o889c4Hax2mKDh1JtIOVqRgyBSaV8OEzromYO25KpSVO4UOL9e+QwveqKvbOEE3X0Q8dlw1j9L6xnV80bbZGr7jGxLs4rNq+T/I7fbqpjJ3Fx8ioy00OZae5/DBb+QPrQ7oU8xaZFBhV14nUAEjPRwjqFzGsKCWjm2xz+89CqNkJp2v7mFSMRhfFQquVN6MepYQ03IyUjXrpg2hcpbrVRXP854x6N2gY1K1G1fy1QIQwzzrr3r5eSgMCzlkc4jC4jI=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.exe /rawdata=dHzdosvHrxky8qGWkVc/qLKyEiL2WLhEQS4ptVi4uOQJDiLrIH9rJRxTuCQvRexMAW/Ujza8xDe1g/CoH5+FLH+GDjSW0eJtXolj5jFIGZrzP0n1DWvLe3IOMGjKzuobhP4G9+rbaQy6yMrprMTIpxwgK4SbKBCG/mve6FFdpB6gho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spYRUMdmb+TmzbKZGTN/cdQ4lFcPhLhOtnKaA7y20uHSKUUL7cUtrNTbQBPI7fQc4d9ieCGKuI16ZPjOK9DqhFd0+usNnqydSPhghcAbgptgv6qdKTzuwpTRaiOux1jekkmjU544HxT042UMP7FVAhs5ACwTihOrRVbrdYEOrkWDRCX1wvO+A1oVhRe+CnH3SHwhLvwE6BLHU5KcHyLcQAea8ryAoI7Af86c/mc6lpKmVj9FeOZWAa7HrGgH5l7E86WLC/s4I0Yy9CwGmkRYH95+8k0bkpLK4rHaJyzV9vJV9ytivobPI+3HbNISYYDQ+Jx123CjC6AEHYEAhv5dnudCZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBhKSSJX9sKO0ZC7f2bUGFChYXmaJuYq4aXxB/eWwbhQwERU07FrgR/C+f76+kz6XahEF1VCiaEH/UmXD/C1Ptv+So7K/fLHm8F4na3A0SX+s/xQfAbGGr8h6/5qsAw6YKwbfoodC6aVKm9Ri49UsxN6f2p0XoOq7Ybf3wzOW4biY=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5_user.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5.exe /rawdata=dHzdosvHrxky8qGWkVc/qLKyEiL2WLhEQS4ptVi4uOQJDiLrIH9rJRxTuCQvRexMAW/Ujza8xDe1g/CoH5+FLH+GDjSW0eJtXolj5jFIGZrzP0n1DWvLe3IOMGjKzuobhP4G9+rbaQy6yMrprMTIpxwgK4SbKBCG/mve6FFdpB6gho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spYRUMdmb+TmzbKZGTN/cdQ4lFcPhLhOtnKaA7y20uHSKUUL7cUtrNTbQBPI7fQc4d9ieCGKuI16ZPjOK9DqhFd0+usNnqydSPhghcAbgptgv6qdKTzuwpTRaiOux1jekkmjU544HxT042UMP7FVAhs5ACwTihOrRVbrdYEOrkWDRCX1wvO+A1oVhRe+CnH3SHwhLvwE6BLHU5KcHyLcQAea8ryAoI7Af86c/mc6lpKmVj9FeOZWAa7HrGgH5l7E86WLC/s4I0Yy9CwGmkRYH95+8k0bkpLK4rHaJyzV9vJV9ytivobPI+3HbNISYYDQ+Jx123CjC6AEHYEAhv5dnudCZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBZ63JyCHxp7uqti/1N+3Zc49+hGDS7xgdqcSa88eAc5FAyFAAzey/5QUMBLnNnFPZA52rWgnwWQkzuGfX+u4dGX8GkJxqxvOn5f1G+sj6HAiUqNxn+SKzUmX25uFGB83K4UMpaMZdw3tEHTlUE5mE4q+2LImMIxSl6eo4wYj+8kI=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6.exe /rawdata=tny8MLM7S/WdZVvokZmCBy1UUrkqReGE0ZzALK6RRQHHr8K5weHXx3gMD4IO6b5ZUxNyGlFh5lUOliilPx6AEXktGSGp8lH7JIbcuB3XirIPVIg0AsqhfetjU0bR21CoEku6kQ1tTOEvqr9njuUiRH14SFq3bQG0+HBfksZofP41P49pqpQzKLYs3cTcm+8ymZMmlhQNqnx8NS+Tjpqo/U5Ir3rZo+OnbJX1UfdO+jWXsBZLeAmdWxZzTMcP5Q02bNBwFNyafJgX0v1pDO35flCH+PWb7pigoD73Ni4SwMkeD8LLatj+xkJ3TE6tEhW9kvpR+64YW0nOUKAkt76jSz/c+IWUTvVvbM6m6BLW4cxTO3VBA227QhTJ3hKQSvKlHtINcrE2g7cvFKwQQEKh0m9p9w33EfCGtE+T87EaOUROYdr0VJHMazRXbeRIWDKq2QNOSfgTblKXpv3iA0fcwU69L5IKqMLNQ6txOmzvJXUpIyGsRTmMEQotBDhPRXGPRx5yvOnpm2NuhH6DX8AnG6BI93Lf7J45LfMpORQ1ldmXR6JuBJOar7eQILwYo/mATaGzotAWHwm0IhJWm1gYsMQvhvybTOO/GvsrGsUDj9WolK5mW7Ofor0bIGErCiixDDWpdKOyZyaqaRt88gr6MlGRLMbdFvKEEp4F0KIuEgFGhe0l99RAaZ8oX/gJVcq1XHdfq3rWwJdK4jVdhvm49jnN+WFDzAB2CUqXqSw7IX+pzR8ATGSMzoY43IKsVGJhVbjfdn/6I8TWiyMvCYywzn8II5vmhliTwmuJrxwkKjkE4RsOBOlYCPZFhZqfVlMiW51dVZG8FcPPC96iAVKXnK600YxPDtxflWJKyYLpX/1VJ/tx4x3kR5xn8DQygPXVMU2pfWL+B2dn42gDyA7LzEsp0cIaK1jZv7KikoVANC58nmGxt/v8IYRls6Np5VHE0cxRmiOf47uiQ7B4xYCPYSJ9F+BT6Goq9bCby4jOHnGzGgWV2cZmLOY8+TiF6EyRWjSXrFQFL9xS70USKvdrHV3TM3IDdsNplAfEz/qHnW9Y1aqayskNUUnrljVG0FVUqhwAWSjI9DduCs9surq5XvUd+Y50I03uq1QEbhQuS5Gzu2qUlx0dc1sRoRbgeN72E4Mz/y2vofKb1be3XRZC8D+7GrIWFbaM6Ogzkp27DP98HxmCXComkElDvSEjDRQcqtwTCU4aYWA7e8/Tj44zk57xK16Avnw4mBt/BELtKtMJaRvfTtb5ZgcFR9jqYOBQ1dPB7BgqPPtRghAr7qhiMDyBAqWfr/Vntl6BvCsE103qKjLN88TYIAJhB8enKVyCLjtqmSd/zGvJvEkEzMaTKz48kYCGfwVJhRkpx77kiRTF4ApjRRSZnkxtmL+niPSd9ORBpNW5wnbs6amlugG7dNTN5kZNUGNAhQezfbPhKXaantJAEHNpUCymQY8j0I9VCxkAJCBA1japfX96FkQBqxt1CJpLUnDoUTVH8QdKouZlfUXn7ssClVLPYxFELB7ttoCqNW3awKQ7iXbtbCXak6uhVtR8M2p9oVyaMyEPaWkpaBo06zF3D88pviwMgwoCEqI7z1JA4uMVNZh0EK6SWt4FXbl3s15o4lclIb3XJI5sGwQkz0i2Qn+/ei+18ecJRCqQMArthze0Ih/EKCUHU3nFIEnEULdjrLAnbLn7pZo=
C:\Windows\tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7.job - C:\Program Files (x86)\Senses\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7.exe /rawdata=ug1WvRJuQjHJqGCmGSwbEBsXg4rm0OjGyXMAitApLT1dJFPlVri+5Xgqi3onUssBf+yWXJNkRkzL76QsoDeZ7dFQR8BSpH1DhBncrQUwyvXi6wsDVUR3CfR1rmPQn9lz7xDq+yCdifaP4/v2NJMvyp1e5heKOfoM5kJzYR9VCXpIWaHfT5Mqq79D0CtmC57QhQdhKibbV9LdU0xahg9Hz6/LfAxeDpJ01zgW5xp9+xpT8uC9cBsYSMLskyk3XwmAmKB9J8f34TDWAyRmKZCZnCnQGePkoWTVzcKtnSf3zn4m+n+AciO/jdwiv91mGARilVpRyA2HfCFMtNdyZAaz3xh71iHDKQgc12ensoQZcnFY/urJSPuRiNtj/5d4WMj5dhOfmPwavKSJtYQSLPjqWDCR5GYELzwmWN417tBwPI6lDbExRAPS4/FKXF0t0zU2o2EnJvRGTei7oGYZgKMUAHbMTXoZ+FBpXLFUY0zZyL28GmYt5OPtP0y6LXW8sdwvlKN9Ug8e7Q2nOvElbB+6ALYKEO5suRoO119iJ9/OSoLCHznQSWh5s6jrZi/EDZ3uxCXSSj2g0xmY8/brHnLK6lnzvqeFgUljox17HP41X+6wj20bkC7nW9bplZu9Lf7slTEMVkm33/H+pHTR66rQXZEwKgAGNBzEYADC3PHjNMRvpWTMegZ/wlfPZcsDw9Bqbc2IQZO4KkrA7649LJtElksTg8GM7TQ5tpXBinfi298nMBjq8P3NsXgQ77s2vUYpXhe1h7ZHYjMPuTfyAuJ+IMPix0LHcolki3ZPJWlz3TkfQzJ5NGmOtRkhITaPfmmF2Ws9T6q+fn1ESP3CrwckviqWwEDZLMw4Etd1Sckz7jspKPnw6Uiry7CT3NfTtG9Aep4TCs8r7ZqPefq+RURpi0EiIXgn15h71GDAyzhAhoVE9Ihmy7XaHOGKaHOuO0/wsrHGJzUhhDClfPvjd0m4uuFmkZwvlBS1IAX6gLkxTOqmtC6s/nGlXL4WIYnO8p+aZXJbUrNWCLQC0ZEZlOD97T7wzSEe9hBDdNsQr/HPUl55/hQCWd4B6M4yfFmrOjFeBfR5veK1ALShpCVAsNWseHCtXVKYTBqAmGphFlcTitjGRRaZzqANPZUwVEq0fxe15CELdCqkJQ6DBRo6gtAhj/pYR10M3sshlvyZ/Umtt4w+Sd83rV/MilHwiqBHEhm2cJaKp/ZxbnjfVFjAA2LNotJgr3yXdUJjGga7+xWCT9DQ/AqfE7ao/sRI5v2L3TzX++/GfL58+YoKaPWAKoQ6EWLjC0PWY0eATWyAkeohlJjIqU5NQobqmW3+HmJT7vhqpNY5VGJYq15bWlHydU2iSkl1pb6cy2Fa25oATdhd1D2oD69YmjaNlwbayWKxP3TrX2gKGwv4S+SwHY8T99QD78Tn+HLKHtTwXn2gLs0w9uuYljmF+8PMpCHq6CTN5j/K5+fqau/FOj0RwvKTN7GqEz1cQQDhA4DSiQ2M5gXaPFDE21x12hNJWznKr7n8M4x8
C:\Windows\tasks\526582f0-0aed-4e27-94ec-b1412802ac90.job - C:\Program Files (x86)\HD01-V2.1V16.09\526582f0-0aed-4e27-94ec-b1412802ac90.exe /agentregpath='HD01-V2.1V16.09' /appid=63831 /srcid='002128' /subid='0' /zdata='0' /bic=0F980A9FD14A47009B5BF997C147A026IE /verifier=ec13f6087755a72301617a4cc545279b /installerversion=1_35_09_16 /installationtime=1410889102 /statsdomain=http://stats.newclientonlinestorage.com /errorsdomain=http://errors.newclientonlinestorage.com /extensionname='Information' /torpedoiesleeps=1000 /torpedoieplugins=93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 /monetizationdomain=http://logs.newclientonlinestorage.com /runfrom='task' /externallog=''
C:\Windows\tasks\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.job - C:\Program Files (x86)\HD01-V2.1V16.09\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.exe 002128 0F980A9FD14A47009B5BF997C147A026IE 63831 1410889102 93-0,102-0,104-0,178-288,179-288,180-288,223-288,263-24 HD01-V2.1V16.09
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AIHGXB.job - C:\Users\Jel�nkovi\AppData\Roaming\AIHGXB.exe /infocmdline=aGKpGXQyaHuDDbaxcI1qDYXTuZAc/rvy1MP0q34VzZZfltwx/vcoXOYD6F82Syyj7cnWtimwi55Rz7AQTtmbvgGy0exQjeEKr6p985OalzPYhF/QuIL3qqPfXT+wgx95VCUbvXXXftZHq5j2u74jrLdEFlFBiUhSPf6Yvm/sI6Etsva1D29GOUgSmnIuETlCHCEI6448YMd5dbITRnbPmqVHn0LM0Yq0vuaeTkYPZYGD46mOHhFY3ivsEr/6bjf1KOEqDX2lwyp1lvdfrVWk4oSTX2Q+qPmX+T2dWOIiX9sMH5uV7lyOsCeanbaVJOA4vp2Ish1SgH8P+89EoxAuPH7xsmqpNjsVRCUdgMQs99O2bT7H8PRAepyWDJc3p6kgQB0m70nSTGSDC7tGUUS2yQe7tmw0L95y3DQuB2RT1oWYOSo9rQVVxXdxDFQEwr+piY0+pCStvrfD34op4jLkbUDIfjPSJVJE64EJ8ovTzbo78c/gp1SxzEngrd1x8eZY
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-1.job - C:\Program Files (x86)\HD01-V2.1V16.09\HD01-V2.1V16.09-codedownloader.exe /rawdata=PfWc1PIGXrCCRe+9s6CZac+QUg5mu9AycbpLZA9BABi/GIJjiFG2O/+v5lrWr2ybNywj1I1ym2M9QXVa/0H1olKz2Pn3ni1nz83rKcER2E1L4bqZsHZ45equNiqO4DOCnBwTb+9p0vWU+IzuOuvLiKMwL1Xu6bZ4jGhBF/O5na5b0ys86qqf7HvrQVjXAhOAsniV6KFO5xk1VEeGLeAduQStxTMw3sBUR+VTBWYGJjzpxASj+OPAnP3pIyPljKaZpquMPBWV7CLuYPs2qZhI+nX2NVoQm3a5shRXP5AqfeQMEE4fVOVZUot5QzbwdkH5tQYz2iiNokmvGG6YwSD9GB7gSeQf4MwcJvdvox9F4woaEpZHMfbsLET9ozSqQwPe+poCzXikNknTc80Tra6MPuUERTiKHcVpWSdkFIQx7WW83c2Yo8y4ps6v/XqXNIwUTBySyZyYbD32V6DT4haTNybIscfxv8yi6MDT54wdVNZ/lDingAxf47HCeWl9tsRQYEACwRR9FKyPBsjBifAMWPjdlabzE6vx9XwDmDaNLBGbqiVkuleZqywBEjwBM+qyT8iE+BVkKe77a1dnVeJwCsmjc0EY7sW1KaudWzuZLslKHBhhpMmH8DK3MywvmaN4nuwiechn6Ajc66vxxQfUmkniuwczerrlrnbSwcp8+mmk+nEA/vEQL4IC7k21ylP5E73QLGMJ7HWxLGEZRWpZVgjqMEhAR2SyNNF29wxo+fE4wYH+1dt0qYJAHayQIW6t7PwCsPcXmQWET0V+4cNuS/Q1KCc9T26MGRHV6kWRIrcubKuw7PTHibGqPY8Vn0X5KLQBpEQlo01zDcuttXnTt5PC70MR4c4NOKmLV2l6EThM7ECYJDgH4HlKusjiIhBLw04c4MZs5TLeUbKBaiNk4wQo370ac3MZz8LxLq4efGRE5vN2hTUhlnkiQsXwUGUR1eronL3YWsN6q02BnSpeanBQ8ruR4kEoznTYsSATMcYAqE2ouslcfS1EJBdG5d9yLWm66oWf/kD42sKZf9G0j4dzj3ROUUcc487naTcFY6KiqNIrSFhX5tcC9n5z9wiqBxJMIqjAcO8w5EBAuOOveCuRlK7bZrKcS1B8xmmv7vVsXzsz4/yI5rF8tfSY0oYsOc6fceoe9G4dD7U3446+aA//cEQ6yQFZDRnkfB2aSFA=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11.exe /rawdata=ggOWLD7MisCSiYHjtgUexB8jh2LkKviQeSQm17qHFqzklYw8p4Tg7QPVIokmU2FzwOhjn0RRA3IeFMrb5cTmb2kSKeKVVk88uLUT6CTpE4BL5xpB4NHla1CQB8NBoqNFz/T/Zd6h1G8Fh4MwQWPwqjKaacwgUuig4frSnsSVlRJ197eY0ZGHba8aERKPAduamW6jWnDVACAfTuhp/c3n6t3EsjRP6KypKjiuY9qlNnswDYBqgex3oEptHi6O0+j4SNrDxh7DcPTtdDnwrk/JuHrgb3wT5Adwh7b0VdUJrri57MQaV+u7hYShH1gORgOBY8oWPgFCfl3wo9BIjAAx3wBNlBVL7wskWPXLzXnbMAFQ+7/9qF4blYtC1/hxfGTIHbqzMfR4AJ1C8jcK7SAQJY/J1mV0j0XznazVWVbfS56bXyow3OLcQEJpbGhjb2bAXvUtmAO5spuzN4M3aCHNJ0NfNiOcOLOVxPV+3eW1cyb3+jzg+VNaBzw5aszhM6Z4x+mI2rqBeOv/dpNkG7sWNkXKz9cFOw6h5w07c6g1GEQRjv56CDVEDZCwz30E+EQlP9pSWn0Bx1Creg66mnaI0eH657GpoYrgjLvgZxnkM2Kyq+IEXhsX+HZinJQCvvmVUnUXy3P4EWAadN0MHW8vpHzqwi/e5OSvhOQDbhKks5t7Xj9odcHEoIHJsVLQ+3vG74XA6FsPBXB+stlx3slT+9TecxfDKFSWXGpcJeCQconA/KYIfIVyXFF3SKDkKhyv6mSRIFKi2IHvirqf70TuufftQFy1+eiwl+tjONOCuR1fnEQlzaGbxEZDRJYIj2J58HWXRhBFreIWGgGNdsinOcITiWNq/VsclisgGDtSU8YPQqHtw5ZNlautUImIDrekK0tnAeRMHKAIDrblcBPrm08rxjpFTYIyJL6ftJhlLz53CjfNtSZvjUmvW2yshH59TAPGvgyT/vWsJe0PL2JvjAuX07zulb9Gs+QpdwuY7pteGfEMSd2qJRJViMTr/NQ2UxAjBch0kIBCqjfUIRbiKupXe5iIwqAoYx6HJJR9a46DSvSAkp5p4Uc2ok+sBzSqr4VxL8UCI0/XU2BHv3qZ0k2FLYdK9UXT0mCOS7HQpoahzv8K0Esqp1gVTjmqkQ7XYjvm+ciXWdHknIWvO3ZfUwOEAmc7kJY8FyaTFVqkgn5dfGs9gEXL9zaBMxXA7plFLoVNHuCXRHXJmhovG364D/RkffUyZDkI34NByfhYrxoZDqOiIBBQOxC34WvdlLhDtxJSCpSYWfMYFf7zal+xrh+3EfeQQzK5X/MoH7HtSSR59B8bQQhaBM1xknnRpaA8/rzpz4q2TIyo1ih5LrABl7Mb3bC7J5I7vFObOBRLRMxlRbuh5mnV1l9lN55QF/kylvNqr1ufkKi+MFDNmSzoE4dpIQlwoQSqRg93RyuW5Moy01bEfNDkfAOC2K4F0MvIMTaEFKXjaCZX9+FV9RfB9jY1dhA72I1wFgtbJoF2yghtUQbGfUyFfw9nCptg85zzCVDP6Mt8pf6ntxsDuxn3+JVdfhcbBurEbQp9MWtDHzB8FJDZKV41k0Yi8lyJE/snf+bgOZjjrdhWZRDme1YeU7UBsgj8viSf99cYV7Zs438zS/OZKscMi/sBgOa/OGUingrpweDHhgErkNBW7Kv18VtQ5uNJNdhjWgz7kbdpXMGgZlQwSPs7+oDXj+SbUUvtc+sTFrwjEf+yA/SFMNULQjFyvUOmlYYnyAFMK92k8x1FYpJ2ZZTUHJ2U88rBYgQtLxlLtoCDAdNQq0YFZI2D7hdCUWvOvI4q/48lllxn4XBm2RVXQ/ThUaxC/Z8QChUQqZk949QdiYeuLCAdLL+CpBfTj1gZ56B7ojELyNayCwqt1C2tP3CdvOPFlZDgaIvnGJGht106QmCs5B5T6wZfCsfmTgaDc54Xp16vBP8wksq8fI2YduDq9ZgtBLhWBePNTPtRsZFFRpcbSQDcH66KvXPvw5WORmaHOvMI1tx2Eawud6KGKYEWAXLqJFlZUlcd
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2.exe /rawdata=T+6ab+87RKN8zWjT0yOh4WAkpGZkFeVb+0G7emcJuJYPr9gC76doJQSuCNst+60yorG6xj+MZtBjg5wstRrZ8YdhzBiC6F0xB2m+jRuC9BB4o6JTyXNAfccvP/k+M+t5QalWl188AAQ8/WmmUVYeesJQ8JFVO4YOhobYi0EKMU59o0BuJRbtQnBnkN3xvqGknFSmoHBwaxPp+FtPGXTop7lqNwoVzMr7lgzW5Dil3lSrqHVaxe65C2scntq/eLiW2abQxYpviMHGvMouhQlWuYQLtXpU1LnAjDSc/aj6tF8zAzmuj/BUjT4xi8J95DmQixZwx2pKH5c+ZX8cgPvEA0firdrGYJNKgxJmZckRHEl3W3ioIhzQ7Ggu3SntTqxuy8rh0f+V1aFpL7JCqZDVcvW8zg4wMQ5hHbD6fcs2xnJmQfGwS8Xl6CAgVCCvSq5BU7eP2zD8EE1pordtNiOKfIhcvcOeCxg6nnOsxb+6aPPEKPsGmdfCQGRLkBTcJ5qyw4DDoFk35QmNJGAQ0OoZq3MPw06A4RCujzYGGU2y2b5hYJYlPICp7VsMrcUwVvMDAWx6+iRXvCkS6UmCCN9iHYz3LTYZEv+bI19EPo3Wn4QbGuoSK2OeUhArWI2+g+yUbt7U4TrkVwV2K3xE4JOpRFLoGhGoXGU2/2M1PFs/RfMdaDlBtTaNKJ6Irozb0KscjrKPFKUH2Mfh5IjqubckuNz8X1JgenMfR8RXg7yvklHzfa0nallYtPrkN/BAWwb7DVQLK6YbATu+a1ikyvjwMSbyDTNwtJhgfUcU3/3Kb3Ikw3HuxFxEPdmP0YMjywq32p9lg6s7Oqk6ihy1RNGOBA==
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3.exe /rawdata=V4ih1Vin6Ty+xCIm0HOh+D5NnnokLpTmA4PSy4IrckwiuU2kO6OiPQjY0Vcafc/ZkepHdvMxK6k1CRqMdWp7wX/Ndw+5N4iGoEVFmeLU2PxHThmTbr+dk/bioFSgUy4plIk7MUXUUPu3MZdWM/4WGkIBb/4ikwXuUC2SeJ33z/BkasHXTfR93+5yPcmciGFJuxZGMMNOeryz8ckAnEFzKiapsYFbKRzJ0R2VnKM3am/QCOaf6CG6H1qGsLpsvpFfFYrvVc76iUGw6Wf3HbFygoGetPSkDB9/b4LE+y5ml8PUoCNkPAEs2+1RSs/ujW93bCi3lMzYhMEaE3zB+IXCwAP5qQKHG4LR0GJjzRjnxqEnCoQu1O6krmaPvhBrLNln5HtokNAroSuol0Fes6y23zPSh1uNrHPf0bDwp0cYWNHCBXk6oOcQfe2HvSF290eDdFwUchq7YdXCxHibcAcDh0TDMh1vhUxDxEOF4Wqz4Pzw3k2voyCH4IBJ/8fjIp96ZLbrgVG0v9PJVskSFx0/zHp2el/OjqIJNgcZdnFgI8uwsoZR1cAKFb1pRuB2O1/nPWsTwRkwFFTxeY0UFNfgD3pFMbvj9UhRyjFC51jei6vWzAzbcOCe+8ZmQiDOZTzWWQk0WtW109ZEX7DWK/axzwV1DidxEa01abW8GJB3Uti2aoZYX+MpTxDVsrP4Anspd7KWL35LZgbB82clWj4lHd+ETSF9tSfVuID9Nc6XxLswGZKvh2MdkiM1k97Wv8SBBjzQEYR9i+moRhwTkEpB1TJbdOqLAobR5bcvaYbDjenX0P6cFazAUEgWBgQ5XvvzFqUDPYBHytg1hafVJiQTnnLJ7zaG1sn9RvtyTlBazJiuHW3DkkFtSJY9SBaAjVJldBSq6CCBT0qpqiEUMZKjgocbs/gllMrzNtb4KsMr7URh+PvVJXpx7AGgIn0tEPq1uKzCAMQ/qaEFJGn45V+q8Pm7RuVpHezOh0rYxW8sQvkbdepSaTwaaVHgTk50V0/hLUB6behschfy/EzkMVsSLegWomshzNngcKEZzbkqhBdAcsXik1W8cLMa+k/v0Tct96VarcY/oH0muHKZTzyMZIk8pvHFLPLejEVTRaIpIXq4KGe5WrZNU7Z0I3EssVVorEVduBZmQwJqWGayRQ985ZAxfNrGVTHgxsIyr5M9yfeiVfeubvt42EjEYX7y+5/JY+HCAGQNi3JTSopSLZtmilXmvF8ysjKPtkwu1VqV4HHQCVDw4/HpXMAXI/5tr9u9GDORbbG6CB+S/4nNPLG6pMt511ghg2llJ/rz2cXOY8qAcgodWWJzH0MToejcuWREa4xmt9eiqAFpPRrCHBypC0iz6prF65dHBhyQzUDhTuc0XCZTzFe/XxQAKVZ7qhGotGQjujcUK+d9j7j483NQiHL73eeNhvFcg7/7Z1Y8saNxlWj3i0u5TPKxpBq30E818cE5CAfMuF9Zqv4NO2CMMsJkP3DErZSbEF1BUSUwSxDAqGc4yHaimv1FrsBYuEwzI0hyFqImFKvtt52Dhde9vgQvfbrbjf4z6d1kDjmJCIh76dRWTXNQpgiT1LFL9FIqTGaTNcKNLQpGEjRxY0XZAwaV8DND9BNjATSglqrCZvbpuI7WZVGB4OQ5i0s6DZK+cXzTj41gNmMmMkK5ulj+QNOCephHOndN58Rhl5LxepI=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4.exe /rawdata=iFX2Dv/qfuF50oX5Yi7BViMcSvzLr5HP90QcsRmqsNQ+XdqMoAsCJ3TIXss4YvLiiCMu5XJdZesQSy9y7iH4HI42mmkXFSQUEVpg4ICBzW5QS5L7gS5WaaX00DGVhFDUYfmkg0hiTMAOmhmhPysNSKlefQ9UBw0sslQ/nWrySTypxrXv3JMYq6nYsei69Y0qNofnpkiO39v3rgsDk5BX6JPyVh1s9oj8bS/mRK67lyeVixQxZmKhAdoz5p+kGXssHvTKoQvc+b95V8TDsX/geFaxxzG0D0EMiT/1uBIcAI+dfC47Z5SgAaITDdCaZkZQE286GeuCd0UgmoUbklVt2C5Wrj5exOrKSCb0XOC0XrTK6mUnByOyAUSRVts6VHDQpEmHw5mlwv2BUsrmQlNX4gaZ8EoGQfbb9aOaULVwWODaAtPd+Ylw3QzI1HWsh1X6xNNBAhalUnw6kQyJ4CqMQApGSpaUyt/bia+HOTvMzMWlilX2Ph/ArC98qIQ2kJ8nZB7e7QJBg1io6kwsYpVFb4I5uVQodSGFCNNX8ixjkV1Bs9AU+lkShHAblykmyPT9VobGIJ6a5vrQ51sbOou9LxKD7RYxC+f1Z9GJh56gsWDT2AKlSRaLgpNkwXCOtbrsRQf7DoWhlLDdnDKEQy2zuHoZCFMxf6X1drDmkjn8UuRmKS92faok0a054q+Wgt+bGjxkMgZXO9mFtiHiE4c8oJsWKTHPQrEZta67qwX48sU4863Qgpwm6Fa4iAe2ZaWgGMNcT0ud0VC7ymDqF0ya15+lPXadWSNxR3vhx5yQbSgGS9IkyR1ezArqFdXs+gCVKeP5/KeSMYsuWFj6005WwHdEvIe9vmn9v+E6yzvMMXCMdTJRrwVcMVy2yc/p6RelzT2tc4C60S6qGGXgSIGN7L7Q3lnAXSsSkWXI39nUwEKV1DJd3O3mtR9n26BaF9paB73aonb6jMFfpco79WtvfXNFeII3zD417oC3f5mqPc/OdCGzGs9dqKvYu8fKzl5LVkEEIumrmG9s6erXbVr2RH91LFgxgbVy8d6ArBCPxqwhKlFzswFM6VsBoAV2JKQBycDxH6TZ4e3j9U+Un0L5vEyZvDTNQESk8nTJQW3BTbQYJ84+ovlEdcF7vsMCl7bLOvFrGjGEQBeoKdnJ85q36ioxW6U59H2KyqO+IrI8gl5KURj8hROtXS+XR9hN58V2nJqFboEg5kOIbJKRv1i/yvNRUxesFnWEB4vzF2JpAG5b1eaAR0AiC+RPKupLzAlSiD6Fbe8cyYsP7ViOVoVp5uHfsNGlreiE58NikK82V1cHYPS2b6cn4lzybUE5XW0rLCd48qxvhJiqOzmXjDPkiiHeY5MfWEpaiUBdWDhWzwZ3RCyD+pzjCmoMWzNjATmnCC2haVC4r0pl2Mkhr7s7aMnm7pGvK4CXuGSSeg7+WsmLcEvRw5Bcmtv2INRcaW4cYNEZvbKDaqaP4tqVOnlagm2Q6ujv3tG9Wcb8AttwfwXofcIWqK4fDby8WVx/iCqEN7HOfo1fkfIVpqRT6S5GQ1g0FS5DiwmbPnbxTtwO6uCsoD0LmPUGVdVLB9wnr84XKeZl/KJTSdLPPzt258xcdD06ahc4NDiR4rxeLjZKA1FCVLk4Y7ZW1xGMGfJJn7snpl40KW/fpf/ZrPoRtmKsdWSd14N5tYtVew6FV9NRMlE=
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.exe /rawdata=MyLdHgOohncsvFdJel3wFeXIwOSgOKKO2FBGtcRptbJsusUlx+mxWpFxgbYBvF9H7XIuK/uKFv2OPTZYo+9/sJdHuevJr9hYqcyNFKWo7u0yo39XvCDFY5P2u133eb9HcM9AmxxB6OT7ZBoMCIhY+4uvpwslgqcDcARsMUfm4D+AtDMhFMEPuIu7kF1Yj8l/mSS3gw7EBdSzgapd422DBgl+IxxK/m00SBwKLfF+uBwmuYKEMV3M2aIdxHeeCNblsyVq+Ru6HuWKUrvl1BpJ0BbkZfkPkjTCZTACxC2gSDrnbA9GiK2joUqUIhE1UIusVLDDTbeCRni5sazdUpgr7Dbuq2mSd7mu1j0GZUPWTK8TTuiv0PPdyLSfHDl2e4nDT/96gyLVSBw7jmVRGGPQGM4kuqhRss5sozjrF38brBawyeuPQk2/SVNK+/X9cUUAOdqIgcP5g2i+7Jpxm9NkILLjiXsMu7Y7lA8PLDeBuYOQ0iqrKw937vEKyhEeBQ6qJjgzVoBXtOy4M5tO3+ySicSkV66cKS7+UDqcnD7VlRtcw6gc8qMcwHt4LfXzfLXVebBIZZvlTPnOr5+7ZIxvqMXvIUjTh5cDywCLPyAYfi+V1SQ0hXaNKDdB3E60hyKAArlyAbLfAbWDLjfIPRvurPhnMVzUeoDzp3C7uZ8liG2z+eQYv3XRTKVHpPBExhrrDjjY/Q+bBUJgLUhiFvfMmqr/kgb5YcQvtwq2lEOsczDQAEczXKA3kJq3wl3Q4qjIx6hefwUTdHUF9CVHXBOWHFwJTK5dVkPq8Hc5JK4IYvyBTHpEoBp5joW0tCuCMtqhqElh2XVk1SP4/XdJZHRD0Qo9Jiu5UxWVinTPqhL0q3xIAkoD3q+i1gC0BOrymagHBCXjX9I5+5IeI/NXKOWdQpox7YpKEgKcL4yGCFFYqL35ySwxFZJNT9FTpnl4opdgO9JshkS7oEGqzYAXc33zrvlboZqFa1c4Z6DUuWlQ2VPHMI1yIF+85Idwhb9+aXZ7
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5_user.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5.exe /rawdata=MyLdHgOohncsvFdJel3wFeXIwOSgOKKO2FBGtcRptbJsusUlx+mxWpFxgbYBvF9H7XIuK/uKFv2OPTZYo+9/sJdHuevJr9hYqcyNFKWo7u0yo39XvCDFY5P2u133eb9HcM9AmxxB6OT7ZBoMCIhY+4uvpwslgqcDcARsMUfm4D+AtDMhFMEPuIu7kF1Yj8l/mSS3gw7EBdSzgapd422DBgl+IxxK/m00SBwKLfF+uBwmuYKEMV3M2aIdxHeeCNblsyVq+Ru6HuWKUrvl1BpJ0BbkZfkPkjTCZTACxC2gSDrnbA9GiK2joUqUIhE1UIusVLDDTbeCRni5sazdUpgr7Dbuq2mSd7mu1j0GZUPWTK8TTuiv0PPdyLSfHDl2e4nDT/96gyLVSBw7jmVRGGPQGM4kuqhRss5sozjrF38brBawyeuPQk2/SVNK+/X9cUUAOdqIgcP5g2i+7Jpxm9NkILLjiXsMu7Y7lA8PLDeBuYOQ0iqrKw937vEKyhEeBQ6qJjgzVoBXtOy4M5tO3+ySicSkV66cKS7+UDqcnD7VlRtcw6gc8qMcwHt4LfXzfLXVebBIZZvlTPnOr5+7ZIxvqMXvIUjTh5cDywCLPyAYfi+V1SQ0hXaNKDdB3E60hyKAArlyAbLfAbWDLjfIPRvurPhnMVzUeoDzp3C7uZ8liG2z+eQYv3XRTKVHpPBExhrrDjjY/Q+bBUJgLUhiFvfMmqr/kgb5YcQvtwq2lEOsczDQAEczXKA3kJq3wl3Q4qjIx6hefwUTdHUF9CVHXBOWHFwJTK5dVkPq8Hc5JK4IYvyBTHpEoBp5joW0tCuCMtqhqElh2XVk1SP4/XdJZHRD0Q3XEXiWWGQtz82R0vfmcnKrFNnwfLZIhyByU5u7Y1B9HpZAuOV8kytr9PTFJE1d9jadP47pHEbGzIwzN8Q1SxndhljyVXzY9HeDpUUF2sMXdLHycRpt5R9ieK1D6mEfxvigS1j2K/mQpM80RelaY1Ic1qua7Cc0R3yDLFonaLcH
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6.exe /rawdata=PezbPAEJ6db3Jfbk4roRBkrXICJ3XfThYePZxtRZA0omP2pDSFoDN0vTkBABi/8h5Rfj1xRSowRJ7Q5W04aMHKVyq+z2h9EPZKt4Qq1KRAp4rKuJzLDYNhk00WbSDHDuqfxf4YOr0X9w8/wsP8k7FLU7jvI6m4TNG5ZrxvTE964bay/hF3rWntc2JnqPLp4+mvYd0xFvIvm0hMrr+bVggkkRh82DQ8i/kjzmtdBEGzl3bKN1D1t7GMFMvM3QsYa1x2O5KlKJKqEpShy1MhtodYfVPbJfu53BUGk/cuSzhvENBP8JVOasH9DRkLJ/ThkJrCeLQL7e+BdLi4Dz6O5PMCWxlvqROGyZWeKsCSI1zg51JWL5wi4iIjYpgFUJg/i0qSl+3OuqSUpuaYaPlqvossZuoUGNq84+yTKaqnT3Igt5NDkqY5KWW1evyyu8C3pENIGM2GEh4UW7QKqB2Rz3TlseWG/YaGSJx/M5Loq/tkXaJrJrixCvj6iITRu6AqdGBtFBfs/JgCeGo3L/fQD5Uco3dMQSeracPhBLGXOjTaRDiAtdwyD34MjFmHwDEThDxFzZyBw5Ayr3Xp/eMitcYsFWzVqVGl87jvrMHUhjF5WYnp9zrekckgzYFy+DS44dXjKAQkwy3HGvegKmDck8qWlhRF7NxGkl5nA6MP55GOa1EI8UqkGW7fK6dL2qH5QitmBb51g5GjPeyyIGbaDZkvBGZSjp7f94nhpK8v0ZcgCZ/BeMUbZFN2YTP+15NEuTjYKGy1ZrySUTH7z7r2OAYZmokPFcL/Zk8MmHl1lSEoBx09rhI70fT6U4MxR6IMUBLDfTvUT4yq3EpHnJYwulqgaieO9RPIzwnkVHcKjuRIEvqlXquOHtV3YcN+uHV/7Mp7IRvDSPPRZs21QBceLirXMynOY4F7VNzi2Wz0P5cKOVv1P5xWaS1Qd/abcis6qUqTf84YQJKa6XSI6tA824U3wlYG5Rh/CTj572SUcHeu+TMWs7bnXByeY9JZ3NrDooO1y41uwWCjVm0y1/Pb7Ot6UCCPGsRmtq6Sv7q3r7ka27Mnczk8uc7pm7KskgTjjwUgksTGUYWLC8H8E3b0yZiD6+6V0jmgB+Y4RBIrJe52cXzpi0kw0woaCMQ/gc1Y66jEqJFH8WqVyqE6JG9iNmSApxVAYWoom+/wLfPqQY5lkLth727t6t5LlyvlF0yh82aMipHpAlrR/urwn2KFPzxHcWAaty3QFWu675WXZV1M7gYYvRVR1Mi5lApFTHtxkpNIL0INvFVXn/1sCX4qSUotGyj2R2sOeKeCCt+QMzzIe7f43iRqgy/PnxtcUxeFsxMAXK6UbhSz5if40o290yODzBE+pPP63AUJ5JvGwF7cpYVbEbuGGXBH+hB3F4MXAQGPEjfhIsAuq8mIOwqdec8dayVX2nvuDimRTR5cZTErLnSOrFaLqVIFRGrFHokJi+eygexiI6rbmzQz12jMIZfy+EP3w8M8qOx6iEuBlnjRc6BxQGDm7XdWr5wz+t67EV
C:\Windows\tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7.job - C:\Program Files (x86)\HD01-V2.1V16.09\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7.exe /rawdata=Nfpbjk+tnMNSV1omXAQZURkwOiJQUEh2lLd5SNUVgE/gXhxKVjOlXcrt6dV5en+D7TMpAi2UN6dQl6qppjOvMyJvFOWpqO9vj/j4qD4Z2VX9UAkOp/l1K4PcEaMdkZGnpM6EBXLvRYV6Oz8+U6zbZNOWg+aQQBvTxwNYTjzhIvF/YRD1IlPDotkczL8CnFTkc3YKp/iDEEa+PZrWaZacDPF6bY3eQt9FMFZUL6341tlKt9Cnl2QnlZqkRlc+UYzi8qoPGEumLbZ5bDGmEvSL50FQAn/NuRXk9YDa0/VKgVRZ9UJKakho/p8ArxGRXrJ9iTV29F6IPp4PRFqjG1AlxrN8AUJOUpHEduOJ823Pz2yPUbBPI+6hidr4MOgxVEx3Tfb/xtjxSLSMmSlLuC8bwZnfzGxdDJrUjUQNnm17PP+0/XFbON87pt2Kyn5/IqS2u7A87QxX3Wva3Q27JFYPautJusn0ODd/vVlM4dfSCp0eEZmVMF56hWafYBTVXIAMes5ibRbDxnswuEZGsHkVZXrb8pWR1oGeSifQJgVguc1J1KCxYz4P0DVdKwg534rSm8TChhni4ghuewLLT3mrDRpUiGFBTVjT8WzyvXLYsrN1EwihIS/cvuZ4+X3IzMMQSPQQuvAmiByf3PuOjLv8c9RJa/5W0YF2eZ+L5L60heSIYvGE7BKykOjKktxtfXXflTxxE+WTCDYhWoBfs+5v7q9UaNuRqg0UkjNJT/A6RKs0cZuAiVXAucNT/qILgz0Ewg1VSV5Ri0e4ZotMg4wKa6VXn2lUwxcyfXtRpFixzHB04qDPN194+QGfkMMLz4CpJ640Y7TqOfMB975CN0Z/nzP0IKtJc6p1PGyzWmn6YwabPbMI26wZQk9ND0xhkkE9AESv0cEJT6yn9PBMaikqQcfDy5zNP1dzONjH18PVoi6Pq7Yt/NxeNNgmDR3t/7yStDaUy9YYrUkFUpqsntJDHYTYJ5YDogcHJtknGulVftyUVzTgBmHAEEqHpfOm/yVCPuYkJnY9xjgHfb7bhdkCJxUjLxDAwonbFnVpjz/yG55zvmtm5vXGe52GqhhESOnMXopFRI/PBhZ+wuVy3lt54GYWLj1hPOIsjil7iOpkNMfgBf+b01PZ/jSFzOeJreKWKCcCGH1+XH34eq6aKuuDVR8NtiXbNhuLBBFuG9XYFosba64HAZFYnWFSE+DO6FInpAlBhHhYhaR730omQnHiIe2bR3aB85OkqPNegtYTFpw5+Mpmx01F9AcBqFeNnUnK+LjQZd6UHOZMpRnZqinOzG411UuVhXWvMv8eCNQkcgYJvblW1vlRYlMnDQ+JWrlIvKVuTMWfVtBtNtPfSm1WAw==
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-1.job - C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe /rawdata=w4ArLgQmOgpnD/D2uHFgzINH+v+6oak1cOnvyUDJZd6s7GvD+r1wj79VP7hU08QWhkSsSi0ksLlezD9P8NXToB1pCTDtZgTWKuoGcXphwWBwtuubuC0/i/V/JmkDBiwrOCgqS0Znbg8oO8YwgcQlL28Qmg3Fi2TNEUlpMLjzI1EqeNuxk4jtH9OpKvLF5GmVxN0qD5xkejVAb2hVccVLoHVLC+78vaaFDOthru7shKPyoIxCFP7oufspobBuq8Hfgtcucs9uov+uutFpsMH+1QRrVMlJFODkwRNqKPMJUYd/L6oKFoRBOlUnc9TtEHQD1qlut73UpiXqyo79rQT7Y3r7V01jQoUh81WlrxUeTLrO1nhCBXlBnxCDvdV8qN/2dpeejR1BK2URsG23ql7+BURnX2KrQTSgS0XsRh4CinhSC1HhEPfeaAsM7ue7D7f8jCiIzIdeaQ6Rby7ToGLWJQIF5Ec3NC8I5E/54Btac/+mKTFNReugUfDmz9kIgp2mlEUuq9D52nJm8nxWGwwJCQZ1QuC7O/mfgmchGtx/m0/gdYdXjgtdf1Lhuf3FLD9hr0VHEcPxLllQ1hh+h3uo0U/XhJTxL76XtFUVHqj61yvkxqc1EA6yLkOu7Giz9JilbHiNKNFDe/GCZLU2G7jt5nv4BwFivULwqw+bHm4FdQ+zHJP7sHjRiXEWXQliHYB6mT3Yv4nwfvvQahA3kqZLcrsKsndBwTXKZqde6pa0ROrJvQtewLrFUs1U30DytnDCJh16TBORKBylSIUoozIZt6FlrPob8+Gym3rv0LZLoMtu3EOk0YZgcBVh2zxesnMSWBQZeL/rgPX7fltVtYhNnJUUIHmlAidOZd5HS8Ka+PJKEp2tCwO26CPlRkArlLj1Qg3IyCCruiPWRkXw7zmBG0lu9Xw2emZH8N4wWUHXmmWTiSI9h+h3o1vFEjD8JfIsXjr5BZNUxuRyevKMWaCNflFscPVb95ScbBFIeLoDAAog6lvZuxm9EN8bzqS0gZX6ovWwBRG2/pxYzydcufA1F5cCbjhek0o0CaM4TV9rVHoZ3R1hSO0DOjOBu9mh8E9W/ZGB2B9gjIFbz0/humJyiWxeDCQwLyCtbrOqY1Jy2DSgYE9QC5zMS6zSfnQvV4C5jmu4peEZpPFDLgq6BULlAyCTDOWj9C1BhQoKObe2oTFuVzbnLthSoVVQRapAhY5B9/aShXJ7Z7Qi4UGfNNNFmzDE3tyYHTZCuU2ENC0x5ybzojADLfvyfYz7E8jMvRxcuSJvfKGMlN5ryJpc5Dt+/t8l/+Pqrd4+gcuSahGcg0rmgq7EjPg+zdsPC5mVAoDntm/EEv3FsL1Ad79eYiy9Vg==
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-11.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-11.exe /rawdata=arB5N93fQIn4H0LXB5bwJ5z4jdUX1skU5tg9kTmf0vo0VyWaZ1S8Q3UmQ/ZXUi51UBY92xZx5PtikkLu4jSFyr6uppdGiJUwcCIgYj9V1GwoEUK2LYDei/vP/E03Ax80ncCbpQRc1dbY8WmSxXinwO+xgA679vHS1cyDDBfb7S6xPp5LADvcNvu8QXIXQaVkuEydnwgehiDO1bVP8nlluQPhVoFxEsoAfKAjg6RIEYTzOeU37RdeMaZmq1SpO9ZJHiDcbTGPyKWcOpOGC4bA3DxHsvPe5i2JoQOr1bUFUdpaiUtaBbhV/ZXgLgDm1eBALeF/oZ4g9ow5TGGLA1sMapvZmUIQdiveBGDLmaHL3+nu7QLVPsfjafNobkBaS2adgdtpcTk0AAnSPD5GI6OtLPzxCVuhuB8gEjOVBS24tHtyiXVqymsrGKntq3wM/W83Rjs/ROdCZ7EBLvPqLVr08WJjG/EY5TLzZe965+0hpoeVxxcnU+0lQ/3a8fFsu9MMJiL1iNBgBSg9umMEzLVauk8xAHrlhU40XTYckZoKs6vbAlU6LhvZd7yBkYzjQ0R34IppjVXCHiqOZq6Hv3mAkwbd8/uQJ8plt7DrtvgJLxALKfaBEKD91bG1qlxfqK/xRujjtRlh2fCiTl1PT6cjHWyBNF7rZiYkBUkwgdDx6khup4NLlWOiRZgSzZfEfGeyAi4uXI8hzCLm+yJjc4WHw5avU573mpi40AkX7VguXdC5OLU2cki0fpRvk5pXDAc2tFtJwL8YV/acESInpjxfR4fC4KNaFNO7S3PQQs7l82yNkyFlb7ULZ0Q4xHfUsi8GRR3V/ve6Ov3KWXY33ACaRmkEPLdqneUrj4czI/J87a+Hf6zOuaJIqlYApsfhKhXpbwHX2DyH5p8lDwXj8+lLDiifH4MRljwdMXMr/U1lZVWkEXwuukBxImUnPw4zhC3gsa3XmtuNYjC9K3ksFmD8NirjS8ds81EVrlMszgupY5Q7iAb/PLS/Wj7CtSY7m4+NYP+N9CZFr1ws0zeequW1Cr1e/RUM2D8477Mg2VYp62JzHIDIlkHoA5YY5f+C+BNn+Ij5RxOIAf1yc2dQrA5Dosux1roBtgYkck3I9mBtJCzkw4h91INXljpzk8GsnrhjSFR/qTEwagELaRzGqF5gQBpOn6hoYz2M3DT1TQkz7EcZFurOfgeJXdts8bPvwlcbo5YcDqmYW4BDFmc7Hq1QeuJNL/pPhm1wsSG8X7OUp7/syLFa/ElkG71JPVCwUrypAvzol7GpZZhwbuvmCWRdJ5MIih/zYorI7f/K9gZKNzPtVTPOE3PTxwf18D0fqBH0vjQ9Cro0E++MsNBbBXqI7GoliwdF6xzVhIWyWucLyrlAdhZQq/80zPLwMyyHtQTwCWu8aoINWC5dWVvLceU4P6vj3Xkc71JrnUeHdQUX/AYeqgLGZm0+9AA0I86CnuibtXzZK2Vmeshw8GvoDasEP7ONwU0dPgmI0wnjKxhkflD3GpoEjmfqbbxHr6dO5wIpA1krhfZvX4caUvsCoyCXvNAwSzih09e712lwkYzpffVOvWqea0koa/WMvyCesb87eWyw/IyBEeNEe3VtEFZdoU/5nknsZflb4Eh9LC2luMfC1tKIN+Rer6uM7Hqvzn0Ep0ZPiFSbjz1/3qfS1ELwF/kEjPHacXgknARaW4HHs7uHWzNLSrL9sHyIohR22I7q4P5KngkpA3HZzKx7+Ae9EcjUSJuX+iTiPjZ0TKdvwtdMBptIjAiUDiFTDLdAQtG+awPnoYMQd3MuyafChOOyp85D9zzXdcbAh01XyoxN7bug2dOA1p2BYzhXV4GuOfiGBC6yZqvH61i6HSllu542ZiMWl+LuXswvOC1j8w62aIoXT1sr4sAF56bAaxiAprzuhZS704KXwMYfhfxkuacdNGJ8DCuaBr8Wy24qgiE0dAOV8EdB8ixPOt7a1CPZ9/cEjFdSr7x/sjD1GMJ7xqNLWazea2++IFfDvxjqRBP/L8GwvUGF43nFLPgLlLl0FrmU
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-2.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-2.exe /rawdata=EiSlIwKGwVfKqsWfMhurXhIFQSGsAauFYFVRzOmnJ6XKBYQbSZaAIJcHid+STRXHSFcMGj0ftIIaxrOH3gAfGGapcSJqK1zGnKxyitq2ozJHVe1QYYy3DMmmbEc7JfjQQ7A+yIaPOUCuzGbO2Mc4dQthgrTGkFGHOBGX6IiTd/M4C8UAWTQveV2NUb8X/KSq4dgumCTfgmWEe0hwEwfp68qUNarTG9BFH00v9QuT78ncaFTBn4InZKd7jRPTXAGzGnDnU8hHHcBCZbbv22QnNQhHKpoBACTL8ciHfnZTEPG9ttji6x0mPLZ1Bpvqm2XLVYC75nkmuF0ojpBKjw/3RME8GWGJjbvrvvyrdsNrqzLze2r1G0luuqZatv1ORuNBLlC2KcT7vj4dbWgNjiYVeBxKC4PoYoWo+FqjRkeAiBpKudwkG9xoNPOS1H69m2uO3SNoaAfbauqhmhkUOJ/AMuZXiR9NlbfdBpx0o7EsZ6vVq26yhsp9wOwVpFxIIG9Ti9pup3dOJvZybcIj63CYURY9Ebn3rugoI5xHlE6//XEffDl8vZiJbMtx6LCgDdRoFjbJ/ENC9NRu5mIic/K0vckOjGhPg16ySH72aBoWG2CEP0lzCENYcR8pSnQGQbWY+snyuFUkhAvns3uHEJ3gy8QEm55qo/4RwJyz2ndCTRi59JrWYmzlyZNRyHxSRKsE1nrR5IO1qH7NqCeP2OkrZ1C1vrY1f4pb1fflBi3StjF7oOX1dZp2g12MN7ErbC6bV/5wm6DRRiXXYZmO+tXAc0UUGnmfJmNBK6kHZ/rHRnwGvIxAGVkrOxSFyJtNVsrgWN0lc3IecGASODxT/8+oAhxszqm13Y7gWoYx1t1KkeiSqm7tjCcDiYJmoigzefmYfE0kp8HqEIX2SKU082PEJ6RplPo9ycoeMMoQgNh/tHs7Hco7Tf0rcydDbrv0mGCzH0CyriwMA9W+s3VyoMV7aqFvk/UcgvsnFCaSKgvfZLCkSXhrtf//zwnbv671BAIU
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-4.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-4.exe /rawdata=WcywhtTOze2ok1T3BBqc5HqvRhx33/qMjkG81gkgRjFdr4Ez/inFS7cGa1pFCfxirPRhaGr11SVahCFemgJov1jR9kDEu2GKc1Fd60YA2gIquYZB5yLF1I8fLZPozBodZ+yG198j5F/b1Vpj9qCV4CktwidlsUQMghVSvSqjI/ExqRWnVnbpkD4TS0zd4N/iJcvnjrA5auqPxoyCIordc49Y9Lo4VhQIM/n8VaCKJ2EcsBKn5hsJ3qS22bA5823C5J6Cqgm1NOPsDut9wqURH8djGA2Z7NC+ZuRuHjsV3EhI3lUh4uWTLUSyxmTHE5AOkO19DukGbXwqN6T8wUFTG0ppw66hV5GRz/jzHBP9np90PsGnuj08WWK4eUqexzCKsmA2E9mPHzmNGg3ixOJuLuJUT9sanTZZkkmI5QkqdisNwZf5NwMtQDZALVSyE/8SAEGQ341HDCSwsXx407q7/3ReGsVZKvabuvw05jTPxqiGHVk2O1DNQID6OzjoeDDOwRDi1qh9pVRMXrWzjRJ4WyE8GQImOF/Lotu6XhzuY9I78fWwSEbdX3LQR7kd+e/EssnN4i7yNun/Ip+RSMFo2DwKtZNtt8gp0vSPXv7lXFUv8df3t8dMObH/CTIkxDF4vTVLjfkoIM/r7SaN7G8gcMym/1vsyD9C87xe1il5Gakcqls4QhjeSnAgza8HJkulns1NVjnzKaD1DGQ2pbrWU7ekameGSM3WlIzD52UEhxAefMbBxw8a3SH2JVxyzODt8AOcF2+V/byXpOf/wUhyfYOz9oC6iIcmN05fdBWbiKvrVarXrVUZpTDoMYeaELtqu7jD9lXmg5chP3Caz44NTW2cyv2b4+4pwqkUclCwDyFCqJIVVveStiAB2QeNSneWZYsNbJ92IGLe0r2+h1qI1lnUe+/E5gt5NXGSXe4gUNk90m9I7NXhRE5tDVqLPHn5HgBNvrgKy1VGG366kwgLo8Cg95P4Wm6RU9qwLrXlkalhDJwJP2LOQZoBlE1glbDxuB4/+b9LKo51H8MmM3/LvxV5M7hXrUZES/cQhnhx1uLUKnIlhDlwc6ASHFcoKUdyS2kLKvPRIM4AuiLIGef5L29UAXtgEkWzvEQ3kcuacylumCcrg1vezvoTc0GzBkEGbE7j9OBvS3RuOLfEye0MUJSCAX20o5Ml+zdhl7EhodcDADWTnYl3JKqFoOjndWEpLqT2Hi6BtbF3L+EQu3aMHTskX5QzsWwlvMgI3vxObWaPvsXP6itcvUh6jJSMC2k7/uz6RZPjHhBffHyNAochP4oTdMi2LoYkCwE59vPrepXLfrj9M2jNQcJadAEa5JSgifLMsX8oxhRyC1BajdJEhis/xmRPDvE7U+pq1KvU+wJ66lAxkcGeFaMpPlVwwIMyCOtGyHn2KO+HDhe+Gb5+spnAZ3Oaeyjvqi53CIHXKXUmM2CioWj2/D/hlwbqvr6IVO/guS5PowpJfzqPCVGbtHTPHbeRp8te3yHrv+6E4ztgUSpYzrc8nLtNdIjEIpgdcTjaTW2RxeYOVCtf1SUBfxFfFxpi0MrM4WaVDT5SVI9gJKs4FWtj8576E+MxjLtsUAaheG9Q8y4+P90E9dbHmATL4kFIlRykKrsCirs1Hcl+QDPEg1LNqZulFkKlXxoWspY6yEfQtLLerr6z2Ixoc+QKHa2Yp3b2teSZPULmnKY=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.exe /rawdata=ogOyypMYpzAPkIRlp6Y5kQrLcxUO0bmZM7J+W6yzkWN44oxOafB6gEicAunL4k/S+8sRegIM57yp2b+ql+DPSzuPZD7zSAqUltFjjySzuDppRg6cZL5Yqrgxs44YIiGwog1JI7SAsSkgdnYQ5CbGb+33GooBVLQ7uoEo96CTc2ugho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spX8VtPCogkzN1FL+kBGQ0F61VhPZkUQO76hv0/h2oJd5/GJRCHU1kxzyelI9PA1Ou4qPSPRoLngD5ppn9ifHZHZcl6DQKOlgJpADk2UjBtB4PKfyQGj/9exw23eDiKnj8l7Q+Qi03DSTPHMWzPKkVAsVRlnP1eZaaKvbfhDP/+d0ipiAJxU+rXEzoOQmAhhUtzt3JYkYesZ5sdZdcFFBOS/2kw14d1sfsLuCblfnFSCvXqK0luWaTpQId4qYqYMSEXAN9Tt0/ciQEJah9jPFLsUO00Kwhmor9XbZBCcLFDpHUu53lCn5TBTNEVfxPS8SyI2zhJajRqY+VLIrf22qxJ2ZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBhKSSJX9sKO0ZC7f2bUGFChYXmaJuYq4aXxB/eWwbhQwERU07FrgR/C+f76+kz6XahEF1VCiaEH/UmXD/C1Ptv+So7K/fLHm8F4na3A0SX+s/xQfAbGGr8h6/5qsAw6YKwbfoodC6aVKm9Ri49UsxN6f2p0XoOq7Ybf3wzOW4biY=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5_user.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-5.exe /rawdata=ogOyypMYpzAPkIRlp6Y5kQrLcxUO0bmZM7J+W6yzkWN44oxOafB6gEicAunL4k/S+8sRegIM57yp2b+ql+DPSzuPZD7zSAqUltFjjySzuDppRg6cZL5Yqrgxs44YIiGwog1JI7SAsSkgdnYQ5CbGb+33GooBVLQ7uoEo96CTc2ugho171vrhFvC2GflihYT0UqGxCWHEBzZqGllh5+8czB5emj9uMlPm2hG+AGsEmiu7a3fjg3CbjOrZJUac4O1NhBudRGTyE72b7AS3FR6Y2bOoBajR0EQGllv953lbiDVq6QZZ6ClWFmBFsEq0e35Op2WtbB56j/zpk+1w+U8spX8VtPCogkzN1FL+kBGQ0F61VhPZkUQO76hv0/h2oJd5/GJRCHU1kxzyelI9PA1Ou4qPSPRoLngD5ppn9ifHZHZcl6DQKOlgJpADk2UjBtB4PKfyQGj/9exw23eDiKnj8l7Q+Qi03DSTPHMWzPKkVAsVRlnP1eZaaKvbfhDP/+d0ipiAJxU+rXEzoOQmAhhUtzt3JYkYesZ5sdZdcFFBOS/2kw14d1sfsLuCblfnFSCvXqK0luWaTpQId4qYqYMSEXAN9Tt0/ciQEJah9jPFLsUO00Kwhmor9XbZBCcLFDpHUu53lCn5TBTNEVfxPS8SyI2zhJajRqY+VLIrf22qxJ2ZuHwrjYIlSLoMbmkX9f5i9iUWAkQ8/Cg55vkgtNMzZbCxOAqT7RdNbtfM93Qjg53EgiopeROr7AZrf8f+iJuQaUpVf7kLSUXK6HVb+K+grrKT0vZ2oRHns/70EvsKcAq2dT4jN+MFJ0g2oXJKUi+BxFAWh1lk4qk7aRHHW+RH5LSbKOz6ItpBgCb0EeAqdjOl4dxLBvHSJuiRZkMSPijYAlCKye56WdgI8nVyKzzrXCyxmdyi1fSixvzuk/ZWsb/xiZBkfut3iS5a3aJa4WGpKVhxaq0X8ZC11G4LwD2ljnhMkaqd3CT91TIU9MeRGYQkurB4zMhTTFazBQtdLQiBZ63JyCHxp7uqti/1N+3Zc49+hGDS7xgdqcSa88eAc5FAyFAAzey/5QUMBLnNnFPZA52rWgnwWQkzuGfX+u4dGX8GkJxqxvOn5f1G+sj6HAiUqNxn+SKzUmX25uFGB83K4UMpaMZdw3tEHTlUE5mE4q+2LImMIxSl6eo4wYj+8kI=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-6.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-6.exe /rawdata=G4RJp8Z9LGlF7IY8hhCXt/+ZpS9Tha+/Mwgzj9k8KjU/oaK16lUseWcFRmEY0tD0gjCcAG9I2QL7niRhI/BXvWaDQ4q+qkuIOyigTM0QhYJZqRuTykHzAW4nCEpeaXFJWE8oIhduXK1llPll4wMd3ynf0m48NNsu47OSM4npkIguYvsd6PtpzrDqDQAqMQq9MUasuD6ydJk/1cF1pKtZ1i7rhrZuvXw+CJRQNRvD6IEGvXEbczBUlnzrMr5xeXuyMMaQyOsLOoFGlUreUocOu1OTSv3Y8xuJj0G9vCD3KnYVYh2Qa3Segq+4Zd96Ekvjgdpqck3PHc0dYcbhbEdNL2yBOmccec3T7IpS8L+yco5JZQMicreu2cJeAh8ngM+75341PsYTmkD9gY7gowEzvWA/IrQgydjmv+lr3/cjRWfci+op2gDXkQc+yN1sfS4V+yuNEsLSEwp0LWYALAxVRQVvcp86LSaNnIqUFN5vm+Ofo62ir9VPAVzuGfE/gBOPUOr3Rpa2TH2ZT4eRDFFK+H7MrP/Qf0btPs7g3NpMUwI9gHl6ZrblHI39V0178nSE/jwnfeGOlXasuOGlwKAjihL8403zhJG86TgdMYQHGXv891tRnQS/qPJEuAFjLD7EGQywNH/6WGgm9L1qSiytT1xoViv7xiKSO0maJVJbDe8CrNMrwzoXrPJbHltYGs6+AACR55CJ8ISe9w2a9nmvboJWcirrvtky+BrpS4GtoCjEssET9Sc/aaJuidME81Kiy4BEuZSjnRP1hEFVYQtjbf0ij3VWYodOLzSIkMOwkZ1AhtlBurMywSgy22hXNH+VFM8+VwgzTRs+qfXfQ2q238YCbuWka4xurc+0nLs9ohFvebxVIfA8hQv+tIASxS8t+/glS9dwbbfECZgfSkoc2NKsmMTypMq4l9eH2wjPdhIhfHkZHiR1R/77C6YXf61ZBQR6oFHz5kd9t7t728BZLO+UlG7/UGO314hvdMDLfCd0H6r9p4Ildo5cGco2/reBtNWDrGsA68rqCxXOkIoq6O4k40gcoJM0Dc3YYgqHrbyAfe5u2mP06tlN5DeOM/xjGUOmTfQRd5JgKCmpNaYMXVIB39NaLLbFPwDOzKcqcvRgsZJ3PlRkDCaLCq7c06n1ujWcbE8ryDICpuzCyTibB0J/7pPcww3nm/ZppnshJg5URN7v74OxcDm0fMe9l2BMrtJI93+KtlqQRK9uwc0PzQDnLl3a9r6tuqJOPQZCDI+E6+bQTkESYpJHFRSruNwxIxwxFnRRlYEGSM/igMc1qDmJW5qwoSpg6x0kC5Il/nAHg5uVBuLgpj9t1+oF+lGm/KAOWuV9R9ZdgxV+LhFacxMdO5jJPLV/1mZbzFEqa62mbWMvmbODNw9HJ6xYl3vZfXYbWftgHR+yejziho0axGkKgvpUlOqNFc0x0goJCmqh0MwiY2VE2huS9Nbd3sSV/S6AB/lfdZkJIoLQK/CFUOj5F2isylIm/0/KDIBF547yY/9oLbGYNvl+TGwKf+CcxN9OAwBq6B7NBucgo27nrQuy7WBdx9jfp4705/4kuAdechpfRTlOaR6/08q7e2hzyc7ct4YuJZETFLRkG2O4skZi/WNFbNDVkn4zkTiDVe7aFoWPFLF/vX3Tmj93vZoAQ+g7fF5ofk27sBZhCzVSXx+i3I5rp6G6I0RjhTP/luA=
C:\Windows\tasks\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-7.job - C:\Program Files (x86)\iWebar\ece32665-c3ec-4c19-9847-29ed7fb0c7b8-7.exe /rawdata=kmHNAC4sIlTb6n819Pct8iDk39691gp3fePgJtLAj8sT3O13SagOejQoyoZiwcJrk+SFyvAIkg/9ia7HrR2gzBufUi1Ihjm+dPMVuW5dU3nqCMvt4ib0ktJH51+cbjsHLuLlNjbkarpMWHVfS9pW/7n68W8IfAWVYXF9stiQJhtIWaHfT5Mqq79D0CtmC57QhQdhKibbV9LdU0xahg9Hz6/LfAxeDpJ01zgW5xp9+xpT8uC9cBsYSMLskyk3XwmAmKB9J8f34TDWAyRmKZCZnCnQGePkoWTVzcKtnSf3zn4m+n+AciO/jdwiv91mGARilVpRyA2HfCFMtNdyZAaz30fmdJDIqxrw6R9zcec9cTEX3k9HoDPJ2PNmNRtZAxJZPJ0T2zB7bCvBmao73wOzrH/9kX2lbSpU3ZLT0L/O/yDVc9sW8D9650V7lqtHBd2DO8knCLnSw9aID/0ef46SkL12pX4i1orzmtf3Ng/hLXRfER7Jt+kgNFJKdvK+3CitQp5b8vQUkbIZHgfnm+cSogb6GO+Eyy1u3xVBD1Zpm414PUArZ0zjk/2r49GzWnVurszpt3e4/xLsivgpfQ7/r92QD0Fv6/3WAl1v3CBs047/2MTHW43Ddf8JlkE8TmILDDDHt6NJmDpLGOMpyTt7OTixOkG60FpRjUjlCfhiqfwxZq3KkLkkJAjujCeeqElFyvK4GdypwGMxWFyrK+iLA1DKjALp9bHc2VnJd2fq7+MqMWXMa8qZM788hI/lJU+vGtjyHXdLcqskHjlGeBV/4QHeh7yDvN7HaWHEl3BASZgfgilteRbTl9GT+Y9kLvypbK1k/wxj+sTWM7+pe8GetHatIYW5CemnMIdJYve1IvsanQ2pEknlG8nC1PWBMeiovw6OU2Z/eFOCiQ5l4tIhvE1ypekv1MeDz8D87cnAUwQomzStmFlLghn0/c2mySMmZNcms2xdJZ/onXVOmB47tdp3sknnZJRYcMLWj8mkUOmNcGCn7GtwPqqOFjxWSnfTcNOsuvrElRdsdwvSsfAtiJm/43uVq9wBOLnae+3q6XW9G8FuDPd9jc5bxP1McRBKNogGOZEAczHDsDeqSpCgjxoyYpMTbE1mzA1mYwPD3k9EvNlpJ0ZHWW0BVwkpnspIkkdS/k1xRtyBqyhlvWKffAwvxJri5FaB3XaXNJ35jfGp2vrm5ZHtHsc1RfT4dy4/JTX5Ys+mjHPZ7shqfRnCAV3rp1HgAVlQL1ooSHGlJoi4C1+IVgrkvG9ibl5kJnYAJjrnrtz8QfK+AY1qdz9v+pUB7y8X3byRXbEb/YsIchRfvrOUBxHRCUXBw7Wd2xrUVcUgRnFjmKT1APGa6/oHaTZ36hQCu2+e0pMJ1vU54n4icy3ePAtQmBcCdMb2wBZS6HDUWw0fh5Lil1t46rEr6MnyLiGKF2osIezym8wUPgk1qYIbW+B7wuiPd8mqQWYecPepNrxEvjCjZV3V2RP6CZxHQ5Js+ABGU1e8LjFiaexMLS4tqGz8v0xiG9AANSJ8CzpyBP3WadDxhrawhRbvpotnP1lA5bFAoyx98UC9anERrwlI1P5SvFhxWvQVMCy5ZvamKIGsEMWH8jclM2Ww7wjx9SfDlCi2mOxaz34LmcnqiUViHHY2dZ7dh81irsF5wEZ1Q6hu3SAmBBZ7KttWlc4ztb+Acxfa9r40XKlFMHo=
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\KEAYWJIF.job - C:\Users\Jel�nkovi\AppData\Roaming\KEAYWJIF.exe /infocmdline=bDbRLKsyRUJ0Ord5FvY7c2rEIa57QvfRk8grogpxIO+qeeAQvA0PnFu9bGtnYYLuzX1gx8An1xGwycpIGOmuG1sh9NKF2zAaV/rSZsbVSvoJAXAHJ372iie/UuKe4u5Fz/OlfXNbIyQQ2M1sQ4QpEbR4MSt7p0gP5Rg/Kh988Gq3TxdZREo7T9bHiMm4pN7Vvvc452dcNJW0pcOONJQtYBU7vK5sKl5BxXuk7Y62uzFvFPdGysh6d8IDj7FCGaMHLqOWN29rtVhOlLDs43nQIpwglCVjr+PUP8JgeVf1J9pp/vzpFygVFx/vACWrmM+mMklFh4wUAZdeZ+vlnwCidgw6HdXUEzqpvEFinmzhLTVoAMyDbYa9ittbS7fGdH7xyJKCsr8hoYbvxoLSYNu1kgi8M8FkyHMsYqjMvkVbU9ZQWVO0l324DdfaqSZtkFvi9i9/vY3zoTrUOoq1+DXa5dgXCWSAz9sUfq41YNM9lzRMiuokW/rnc0zamL7rFldGsZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\QWMS.job - C:\Users\Jel�nkovi\AppData\Roaming\QWMS.exe /infocmdline=qJH3rHn13PRo7FJKjZ3YMJQp+xefapZst19IGRvZ/o+H0P3pZV3Z9vyytf16TPTf4iAXY+bC6kifD7uRWII4I+i//K4MmAvUElTTpC/0aZf2QpO0dXV1rEeKtv8ZWlE2XJwT5ks8QLCB1+B1lVCxT6Zi7kOOP67YHSWoAYcTqO4St96aHlhgHahLKYNCaw8e1FyvAu+vwT5XaQ0W3cIFv7AKYtFDk04ww9Dpb7eaCBJGcP5Qxh7nB0JpzsQuXLXadhbnZhAkLsM9UMXw9Jr7Bov326vpsceWwp/YHmiLvKX9giB59lZS9n8NM4hC4nJAk0VOuXNVb4EeAAououumjZ3JkQFZupM1K7jsLRry65uBieSrU3jow+9pWVApF3TFwyt34wAcBb0xWLMjSLpKf07tat/UGlFO7aB1lIv1GNqobdQ4Fcrnm5XNnlaFO4IIWkY+mzoHDRkHoiczInUTTR/2YxUHpsukzS6495cOyb8f4es3WifLpCdJZokh/lfk
C:\Windows\tasks\SpeedUpMyPC Maintenance.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe -m
C:\Windows\tasks\SpeedUpMyPC Startup.job - C:\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe
C:\Windows\tasks\YJVIWV.job - C:\Users\Jel�nkovi\AppData\Roaming\YJVIWV.exe /infocmdline=TQKuoSRc0EA6abS0HXeKvOW9hmJb/fpyEVl3nm4IcoCD78pVTKHX4w+OWX+Hvbn5yN59BQ5gnwtLaQA3aAw+UizANBlg+YbtTFbVFR4bYjjKdEjqbS/QPfKcrRIOUf03MG4xUfWM0P89wJo+qjBgh84xMIz53iZk/nlM3GhVByQ/5/dKLBQLcXbEQb38PFTJXUs1jNiPv3/Hc1S5M1BTj6mweKi/7W5fMU+cv9E3DZYfBQkPGvM9HqKEsg2PQvSxJkvc1V18/FaZKZ8soNRXKNx6GD0yltHwELE51vLslYgawyFHt40DfXlaCJw5PXoKL/7VThCQrLZv1Sw+/TTdSG3Tr55BqmYaV/Fa6Azu/KTx1VKYcGrzmciTQIbga3s5rPWjhGOWoCsfRUuDcCwjydtnv0R2fANygSRzvOJ5+ojALA3RP1WIZs/DyngdpiicFnvZ5HGPZAO62TnIqx3W0p74t/hXKGvZ0yxtCzGJwTLdUL6CQ9L2CPGfp42kDGKT
=========Mozilla firefox=========
ProfilePath - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.55.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\extensions\
ROUAILDE73397174@UXGZI17268980.com
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\searchplugins\
bingp.xml
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191115}]
Senses - C:\Program Files (x86)\Senses\Senses-bho.dll [2014-09-25 621976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611511123}]
iWebar - C:\Program Files (x86)\iWebar\iWebar-bho.dll [2014-09-27 587168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-15 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-17 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper.dll [2014-06-15 434024]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-15 4085896]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2013-12-06 389120]
"FixMyRegistry"=C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [2014-05-26 1886840]
"Akamai NetSession Interface"=C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe [2014-04-17 4672920]
"Game Fire"=C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [2011-12-02 44032]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"cz.seznam.software.autoupdate"=C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"GoobzoYouTubeAccelerator"=C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2014-09-25 2227048]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-09-27 18:33:37 ----D---- C:\Program Files (x86)\trend micro
2014-09-27 18:33:36 ----D---- C:\rsit
2014-09-25 16:53:05 ----D---- C:\sh4ldr
2014-09-25 16:52:32 ----A---- C:\Users\Jelínkovi\AppData\Roaming\AIHGXB.exe
2014-09-25 16:52:22 ----D---- C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2014-09-25 16:51:38 ----A---- C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF.exe
2014-09-25 16:51:27 ----D---- C:\Program Files (x86)\Senses
2014-09-25 16:41:06 ----D---- C:\ProgramData\YTAHelper
2014-09-25 16:41:04 ----D---- C:\Program Files (x86)\YTAHelper
2014-09-25 16:40:33 ----D---- C:\Program Files (x86)\YouTube Accelerator
2014-09-25 16:39:26 ----D---- C:\Users\Jelínkovi\AppData\Roaming\istartsurf
2014-09-25 13:05:52 ----D---- C:\Program Files (x86)\Enigma Software Group
2014-09-25 13:03:56 ----D---- C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-25 07:13:35 ----A---- C:\autoexec.bat
2014-09-25 07:11:49 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2014-09-24 06:57:29 ----A---- C:\Windows\SysWOW64\tzres.dll
2014-09-17 19:40:33 ----A---- C:\Windows\SysWOW64\tasks.dll
2014-09-17 13:04:28 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Ubisoft
2014-09-17 13:04:28 ----D---- C:\ProgramData\Ubisoft
2014-09-16 19:40:33 ----D---- C:\Program Files (x86)\GetPrivate
2014-09-16 19:40:29 ----D---- C:\Users\Jelínkovi\AppData\Roaming\GetPrivate
2014-09-16 19:39:31 ----A---- C:\Users\Jelínkovi\AppData\Roaming\YJVIWV.exe
2014-09-16 19:38:57 ----A---- C:\Users\Jelínkovi\AppData\Roaming\QWMS.exe
2014-09-16 19:38:35 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-16 19:38:31 ----D---- C:\Program Files (x86)\HD01-V2.1V16.09
2014-09-15 16:26:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-15 16:26:36 ----D---- C:\Program Files (x86)\AGEIA Technologies
2014-09-15 13:18:27 ----D---- C:\ProgramData\Firefly Studios
2014-09-15 07:46:51 ----D---- C:\Program Files (x86)\LeeGT-Games
2014-09-15 07:43:17 ----D---- C:\Program Files (x86)\ISLAND TRIBE 2
2014-09-15 07:16:39 ----D---- C:\hry
2014-09-11 18:25:59 ----A---- C:\Windows\SysWOW64\ieui.dll
2014-09-11 18:25:57 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\vbscript.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\msrating.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 18:25:56 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 18:25:55 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iesetup.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iernonce.dll
2014-09-11 18:25:54 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 18:25:53 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 18:25:53 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 18:25:52 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 18:25:52 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 18:25:51 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 18:25:48 ----A---- C:\Windows\SysWOW64\iertutil.dll
2014-09-11 18:25:47 ----A---- C:\Windows\SysWOW64\wininet.dll
2014-09-11 18:25:46 ----A---- C:\Windows\SysWOW64\urlmon.dll
2014-09-11 18:25:46 ----A---- C:\Windows\SysWOW64\jscript9.dll
2014-09-11 18:25:44 ----A---- C:\Windows\SysWOW64\mshtml.dll
2014-09-11 18:25:43 ----A---- C:\Windows\SysWOW64\ieframe.dll
2014-09-11 18:22:15 ----A---- C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 06:40:43 ----A---- C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 06:40:15 ----A---- C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 06:39:54 ----A---- C:\Windows\SysWOW64\kerberos.dll
2014-09-11 06:39:53 ----A---- C:\Windows\SysWOW64\sspicli.dll
2014-09-11 06:39:53 ----A---- C:\Windows\SysWOW64\secur32.dll
2014-09-10 14:24:12 ----D---- C:\Program Files (x86)\Universal Interactive
2014-09-09 15:55:50 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Tibia
2014-09-09 15:54:17 ----D---- C:\Program Files (x86)\Tibia
2014-09-08 16:11:18 ----D---- C:\Users\Jelínkovi\AppData\Roaming\PlayFirst
2014-09-08 16:11:18 ----D---- C:\ProgramData\PlayFirst
2014-09-08 16:10:59 ----D---- C:\Wandering-Willows
2014-09-08 07:17:16 ----D---- C:\Users\Jelínkovi\AppData\Roaming\vlc
2014-09-08 07:16:45 ----D---- C:\Program Files (x86)\VideoLAN
2014-09-03 11:59:23 ----D---- C:\Program Files (x86)\bitComposer Games
2014-09-03 06:02:37 ----D---- C:\CFLog
2014-09-03 05:50:32 ----D---- C:\SG Interactive
2014-08-28 10:06:00 ----D---- C:\Program Files (x86)\Game_Maker8
2014-08-28 08:40:59 ----A---- C:\Windows\SysWOW64\gdi32.dll
======List of files/folders modified in the last 1 month======
2014-09-27 18:33:39 ----D---- C:\Windows\Temp
2014-09-27 18:33:37 ----RD---- C:\Program Files (x86)
2014-09-27 18:31:02 ----D---- C:\Windows\Tasks
2014-09-27 18:30:59 ----D---- C:\Program Files (x86)\iWebar
2014-09-27 18:30:25 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Mumble
2014-09-27 18:07:54 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz
2014-09-25 16:53:16 ----SHD---- C:\Windows\Installer
2014-09-25 16:52:22 ----D---- C:\Windows
2014-09-25 16:50:14 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Skype
2014-09-25 16:44:29 ----SHD---- C:\System Volume Information
2014-09-25 16:41:06 ----HD---- C:\ProgramData
2014-09-25 16:40:38 ----D---- C:\Windows\Prefetch
2014-09-25 16:40:35 ----D---- C:\Windows\SysWOW64
2014-09-25 16:36:55 ----SD---- C:\Users\Jelínkovi\AppData\Roaming\Microsoft
2014-09-25 08:06:29 ----D---- C:\Windows\rescache
2014-09-25 07:12:48 ----D---- C:\Program Files
2014-09-25 07:11:49 ----D---- C:\Program Files (x86)\Common Files
2014-09-24 19:11:31 ----D---- C:\Windows\winsxs
2014-09-24 19:11:24 ----D---- C:\Windows\SysWOW64\cs-CZ
2014-09-23 17:32:09 ----D---- C:\Program Files (x86)\Guild Wars 2
2014-09-23 17:01:32 ----D---- C:\Program Files (x86)\Steam
2014-09-20 18:40:25 ----D---- C:\Users\Jelínkovi\AppData\Roaming\Guild Wars 2
2014-09-18 17:59:07 ----D---- C:\ProgramData\Skype
2014-09-17 13:02:22 ----RSD---- C:\Windows\assembly
2014-09-17 12:52:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\WinRAR
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\Mount&Blade
2014-09-17 12:42:27 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-09-12 07:13:39 ----D---- C:\Windows\Microsoft.NET
2014-09-11 18:31:45 ----D---- C:\Windows\SysWOW64\en-US
2014-09-11 18:31:44 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 18:24:35 ----A---- C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-10 18:49:36 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 14:15:27 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2014-09-10 14:15:09 ----D---- C:\Users\Jelínkovi\AppData\Roaming\DAEMON Tools Lite
2014-09-07 11:18:48 ----D---- C:\Windows\SysWOW64\drivers
2014-09-07 11:01:39 ----D---- C:\Program Files (x86)\Common Files\Steam
2014-08-28 11:23:42 ----D---- C:\Windows\LiveKernelReports
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\SysWOW64\drivers\aswRvrt.sys []
R0 aswVmm;avast! VM Monitor; C:\Windows\SysWOW64\drivers\aswVmm.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys []
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys []
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys []
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys []
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R3 3xHybr64;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybr64.sys []
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys []
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys []
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys []
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys []
S3 X6va026;X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 []
S3 X6va027;X6va027; \??\C:\Windows\SysWOW64\Drivers\X6va027 []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-15 50344]
R2 YouTubeAcceleratorService;YouTubeAcceleratorService; C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe [2014-09-25 1510248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-27 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-04 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-10 267440]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-27 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-04 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 npggsvc;nProtect GameGuard Service; C:\Windows\system32\GameMon.des [2014-05-15 3191392]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-08-28 833728]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: Problem se spamem a internetem
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner


- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Problem se spamem a internetem
tady jsou logy:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.3 (09.27.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jelˇnkovi on so 27.09.2014 at 18:52:49,74
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622192215}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622382231}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622192215}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622382231}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611511123}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611511123}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
Successfully deleted: [File] "C:\Users\Jelˇnkovi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\Users\Jelˇnkovi\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
Successfully deleted: [Folder] "C:\Users\Jelˇnkovi\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted: [File] C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\searchplugins\bingp.xml
Successfully deleted the following from C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\prefs.js
user_pref("browser.search.defaulturl", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2
user_pref("extensions.crossrider.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.toolbar.mindspark._gcMembers_.firstKnownVersion", "6.52.4.4721");
user_pref("extensions.toolbar.mindspark._gcMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=928BD6D8-FA16-405A-AAA6-4B25324335AD&n=780c4817&p2=^XN^xdm246^YYA^cz&si=
user_pref("extensions.toolbar.mindspark._gcMembers_.initialized", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.installKeysSource", "LocalStorage");
user_pref("extensions.toolbar.mindspark._gcMembers_.installType", "XPI");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.contextKey", "");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.installDate", "2014070807");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerId", "^XN^xdm246^YYA^cz");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerSubId", "CH_WEAT_INTL_CZE_35");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.pixelUrl", "hxxp://weatherblink.dl.tb.ask.com/install_pixels.jhtml?partner=^XN^xdm246^YYA^cz&coId=e6483fad9c12
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.success", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.toolbarId", "928BD6D8-FA16-405A-AAA6-4B25324335AD");
user_pref("extensions.toolbar.mindspark._gcMembers_.isCompliantUninstallImplementation", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.lastActivePing", "1405866303808");
user_pref("extensions.toolbar.mindspark._gcMembers_.lastKnownVersion", "6.52.4.4721");
user_pref("extensions.toolbar.mindspark._gcMembers_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.keywordEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.partnerPixelFired", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.successUrl", "hxxp://download.weatherblink.com/installComplete.jhtml");
user_pref("extensions.toolbar.mindspark._gcMembers_.toolbarCollapsed", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.weather.location", "10001");
user_pref("extensions.toolbar.mindspark.lastInstalled", "weatherblink@mindspark.com");
user_pref("keyword.URL", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
Emptied folder: C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\minidumps [42 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 27.09.2014 at 18:58:49,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.310 - Report created 27/09/2014 at 19:07:37
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jelínkovi - JELÍNKOVI-PC
# Running from : C:\Users\Jelínkovi\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : YouTubeAcceleratorService
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Goobzo
Folder Deleted : C:\ProgramData\YTAHelper
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\GetPrivate
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Uniblue
Folder Deleted : C:\Program Files (x86)\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\YTAHelper
Folder Deleted : C:\Program Files (x86)\HD01-V2.1V16.09
Folder Deleted : C:\Program Files (x86)\Senses
Folder Deleted : C:\Users\Jelínkovi\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Jelínkovi\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\JELNKO~1\AppData\Local\Temp\PodoWeb
Folder Deleted : C:\Users\Jelínkovi\AppData\LocalLow\Goobzo
Folder Deleted : C:\Users\Jelínkovi\AppData\LocalLow\Senses
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\GetPrivate
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\Uniblue
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
Folder Deleted : C:\Users\Public\Documents\YTAHelper
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
File Deleted : C:\Users\Jelínkovi\Desktop\FixMyRegistry.lnk
File Deleted : C:\Users\Jelínkovi\Desktop\YouTube Accelerator.lnk
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : SpeedUpMyPC Maintenance
Task Deleted : SpeedUpMyPC Startup
Task Deleted : YTAHelper
Task Deleted : YTAUpdate_logon
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-1
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7
Task Deleted : 526582f0-0aed-4e27-94ec-b1412802ac90
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-1
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [GoobzoYouTubeAccelerator]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FixMyRegistry.exe
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\HD01-V2.1V16.09
Key Deleted : HKCU\Software\AppDataLow\Software\Senses
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\Goobzo
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\HD01-V2.1V16.09
Key Deleted : HKLM\SOFTWARE\Senses
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Senses
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17280
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v32.0.3 (x86 cs)
[ File : C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [12326 octets] - [27/09/2014 19:00:02]
AdwCleaner[S0].txt - [11325 octets] - [27/09/2014 19:07:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11386 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.3 (09.27.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jelˇnkovi on so 27.09.2014 at 18:52:49,74
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622192215}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622382231}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622192215}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622382231}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611511123}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611511123}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655195515}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655385531}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666196615}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666386631}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644194415}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644384431}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611191115}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611381131}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}
~~~ Files
Successfully deleted: [File] "C:\Users\Jelˇnkovi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\Users\Jelˇnkovi\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uniblue"
Successfully deleted: [Folder] "C:\Users\Jelˇnkovi\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Successfully deleted: [File] C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\searchplugins\bingp.xml
Successfully deleted the following from C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\prefs.js
user_pref("browser.search.defaulturl", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2
user_pref("extensions.crossrider.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.toolbar.mindspark._gcMembers_.firstKnownVersion", "6.52.4.4721");
user_pref("extensions.toolbar.mindspark._gcMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=928BD6D8-FA16-405A-AAA6-4B25324335AD&n=780c4817&p2=^XN^xdm246^YYA^cz&si=
user_pref("extensions.toolbar.mindspark._gcMembers_.initialized", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.installKeysSource", "LocalStorage");
user_pref("extensions.toolbar.mindspark._gcMembers_.installType", "XPI");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.contextKey", "");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.installDate", "2014070807");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerId", "^XN^xdm246^YYA^cz");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.partnerSubId", "CH_WEAT_INTL_CZE_35");
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.pixelUrl", "hxxp://weatherblink.dl.tb.ask.com/install_pixels.jhtml?partner=^XN^xdm246^YYA^cz&coId=e6483fad9c12
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.success", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.installation.toolbarId", "928BD6D8-FA16-405A-AAA6-4B25324335AD");
user_pref("extensions.toolbar.mindspark._gcMembers_.isCompliantUninstallImplementation", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.lastActivePing", "1405866303808");
user_pref("extensions.toolbar.mindspark._gcMembers_.lastKnownVersion", "6.52.4.4721");
user_pref("extensions.toolbar.mindspark._gcMembers_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.keywordEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.partnerPixelFired", true);
user_pref("extensions.toolbar.mindspark._gcMembers_.successUrl", "hxxp://download.weatherblink.com/installComplete.jhtml");
user_pref("extensions.toolbar.mindspark._gcMembers_.toolbarCollapsed", false);
user_pref("extensions.toolbar.mindspark._gcMembers_.weather.location", "10001");
user_pref("extensions.toolbar.mindspark.lastInstalled", "weatherblink@mindspark.com");
user_pref("keyword.URL", "hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&");
Emptied folder: C:\Users\Jelˇnkovi\AppData\Roaming\mozilla\firefox\profiles\n8ca5hhb.default\minidumps [42 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 27.09.2014 at 18:58:49,62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.310 - Report created 27/09/2014 at 19:07:37
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jelínkovi - JELÍNKOVI-PC
# Running from : C:\Users\Jelínkovi\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
Service Deleted : YouTubeAcceleratorService
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Goobzo
Folder Deleted : C:\ProgramData\YTAHelper
Folder Deleted : C:\ProgramData\AlawarWrapper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\GetPrivate
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Uniblue
Folder Deleted : C:\Program Files (x86)\YouTube Accelerator
Folder Deleted : C:\Program Files (x86)\YTAHelper
Folder Deleted : C:\Program Files (x86)\HD01-V2.1V16.09
Folder Deleted : C:\Program Files (x86)\Senses
Folder Deleted : C:\Users\Jelínkovi\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Jelínkovi\AppData\Local\AlawarWrapper
Folder Deleted : C:\Users\JELNKO~1\AppData\Local\Temp\PodoWeb
Folder Deleted : C:\Users\Jelínkovi\AppData\LocalLow\Goobzo
Folder Deleted : C:\Users\Jelínkovi\AppData\LocalLow\Senses
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\GetPrivate
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\istartsurf
Folder Deleted : C:\Users\Jelínkovi\AppData\Roaming\Uniblue
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
Folder Deleted : C:\Users\Public\Documents\YTAHelper
Folder Deleted : C:\Users\Public\Documents\AlawarWrapper
File Deleted : C:\Users\Jelínkovi\Desktop\FixMyRegistry.lnk
File Deleted : C:\Users\Jelínkovi\Desktop\YouTube Accelerator.lnk
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : SpeedUpMyPC Maintenance
Task Deleted : SpeedUpMyPC Startup
Task Deleted : YTAHelper
Task Deleted : YTAUpdate_logon
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-1
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-11
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-2
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-3
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-4
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-6
Task Deleted : 0464758d-0fde-4a9d-bab3-cf5e9bb09d42-7
Task Deleted : 526582f0-0aed-4e27-94ec-b1412802ac90
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-1
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-11
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-2
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-3
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-4
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-6
Task Deleted : c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [GoobzoYouTubeAccelerator]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\FixMyRegistry.exe
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\HD01-V2.1V16.09
Key Deleted : HKCU\Software\AppDataLow\Software\Senses
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\Goobzo
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKLM\SOFTWARE\Uniblue
Key Deleted : HKLM\SOFTWARE\HD01-V2.1V16.09
Key Deleted : HKLM\SOFTWARE\Senses
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istartsurf uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Senses
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17280
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v32.0.3 (x86 cs)
[ File : C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [12326 octets] - [27/09/2014 19:00:02]
AdwCleaner[S0].txt - [11325 octets] - [27/09/2014 19:07:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11386 octets] ##########
Re: Problem se spamem a internetem

- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;
- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Problem se spamem a internetem
tady je log:
Zoek.exe v5.0.0.0 Updated 27-09-2014
Tool run by Jelˇnkovi on ne 28.09.2014 at 9:18:15,77.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\JELNKO~1\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
28.9.2014 9:19:43 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
Added to C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
user.js not found
---- Lines a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831 removed from prefs.js ----
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.coma0cd156
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.coma0cd156
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncdb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncdb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncin
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncin
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.active", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.addressbar", "NA");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.addressbarenhanced", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.asyncdb.was_copied", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.asyncinternaldb.was_copied", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.backgroundver", 1);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.certdomaininstaller", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallationTime.value", "%221410889102%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22002128
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.load_balancer.expiration", "Thu Sep 25 2014 19:51:11 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.previous_page.value", "%22http%3A//www.seznam.cz/%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.user_id.value", "%22148833220e32d9175fcfed266bf0b179%22
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.description", "Lights out for YouTube");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.domain", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.enablesearch", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.homepage", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.changeprevious", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.iframe", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.InstallationThankYouPage", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.InstallationTime", 1410889102);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__defualt_browser__.value", "%22ff%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.expiration", "Fri Feb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules.expiration", "Fri Feb 01 2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules.value", "%5B%7B%22rules%22
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules_verion.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules_verion.value", "6");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_daily_visit.expiration", "Fri Sep
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_daily_visit.value", "1411645871064
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_impression_time.expiration", "Fri
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_impression_time.value", "141164598
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules.expiration", "Fri Feb 0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules_verion.expiration", "Fr
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules_verion.value", "52");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pages_visited_count.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pages_visited_count.value", "9");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_19.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_19.8.2014.value", "23");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_20.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_20.8.2014.value", "20");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_21.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_21.8.2014.value", "10");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_22.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_22.8.2014.value", "3");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_23.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_23.8.2014.value", "13");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_24.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_24.8.2014.value", "11");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_25.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_25.8.2014.value", "10");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_26.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_26.8.2014.value", "13");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today.expiration", "F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today.value", "1");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today_siteunder.expir
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today_siteunder.value
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__verions_data.expiration", "Thu Sep 25 2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__verions_data.value", "%7B%22global_rule
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb._installer_additional_info.expiration", "Fri Feb 01
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb._installer_additional_info.value", "%7B%22asw%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%2200
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerUserIdentifiersCache.value", "%7B%22instal
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledWithHash.expiration", "F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledWithHash.value", "null")
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_notBundledArr_.expiration", "Fr
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D"
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_regBundledWithSoftware.expirati
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_regBundledWithSoftware.value",
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_appVer.value", "47");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_nextCheck.expiration", "Thu Sep 25 2014 1
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.lastDailyReport", "1411645866325");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.lastUpdate", "1411645852113");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.manifesturl", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.name", "CinPlus-2.4c");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.newtab", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.opensearch", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.pluginsurl", "http://js.newclientstaticsrv.com/plugin/apps/638
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.pluginsversion", 40);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.publisher", "Cinema Plus");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.searchstatus", 0);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.setnewtab", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.thankyou", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.updateinterval", 360);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.ver", 47);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.apps", "63831");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.cid", 63831);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.firstrun", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.hadappinstalled", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.installationdate", 1410950374);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.modetype", "production");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.reportInstall", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.statsDailyCounter", 10);
---- Lines awarnerrobertshotmailcom61915 removed from prefs.js ----
user_pref("extensions.awarnerrobertshotmailcom61915.61915.active", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.addressbar", "NA");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.addressbarenhanced", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.asyncdb.was_copied", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.asyncinternaldb.was_copied", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.backgroundver", 1);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.certdomaininstaller", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallationTime.value", "%221411656679%22");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A%220%22%2
user_pref("extensions.awarnerrobertshotmailcom61915.61915.description", ".");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.domain", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.enablesearch", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.homepage", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.changeprevious", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.iframe", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.InstallationThankYouPage", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.InstallationTime", 1411656679);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.__defualt_browser__.value", "%22ch%22");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B0%2C5%2C536879104%5D%2C%22b
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%2263
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%2263C04260A4E7401B9100AB8
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A%220%
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%2263C04260A4E740
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00:00 GMT+01
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledWithHash.value", "null");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:00 GMT+010
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_appVer.value", "33");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_nextCheck.expiration", "Tue Jan 01 2002 06:04:54 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.lastDailyReport", "1009839889604");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.lastUpdate", "1009839889321");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.manifesturl", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.name", "Senses");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.newtab", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.opensearch", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.pluginsurl", "http://js.newclientstaticsrv.com/plugin ... ugins.json"
user_pref("extensions.awarnerrobertshotmailcom61915.61915.pluginsversion", 29);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.publisher", "Object Browser");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.searchstatus", 0);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.setnewtab", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.thankyou", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.updateinterval", 360);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.ver", 33);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncdb_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncinternaldb_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comawarnerrobertshotmailcom61915_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comawarnerrobertshotmailcom61915_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.apps", "61915");
user_pref("extensions.awarnerrobertshotmailcom61915.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.awarnerrobertshotmailcom61915.cid", 61915);
user_pref("extensions.awarnerrobertshotmailcom61915.firstrun", false);
user_pref("extensions.awarnerrobertshotmailcom61915.hadappinstalled", true);
user_pref("extensions.awarnerrobertshotmailcom61915.installationdate", 1009839886);
user_pref("extensions.awarnerrobertshotmailcom61915.modetype", "production");
user_pref("extensions.awarnerrobertshotmailcom61915.reportInstall", true);
user_pref("extensions.awarnerrobertshotmailcom61915.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----
prefs_28.09.2014_0931_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~3\HirezPipeError.txt deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\Tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5_user.job deleted
C:\Windows\Tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5_user.job deleted
C:\Windows\tasks\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.job deleted
C:\windows\SysNative\Tasks\YTAUpdate deleted
C:\windows\SysNative\tasks\Installer_shopperpro deleted
C:\windows\SysNative\tasks\GPUP deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\SysWOW64\AniGIF.ocx deleted
C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\extensions\firefox@mega.co.nz.xpi deleted
C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\jetpack deleted
C:\Users\JELNKO~1\Desktop\Continue installation - GotClipDownloader Installation.lnk deleted
"C:\Users\JELNKO~1\AppData\Local\LumaEmu" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [15.08.2014 14:11]
==== Firefox Extensions ======================
ProfilePath: C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- AdBlock for Firefox - %ProfilePath%\extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[15.08.2014 14:11]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Page"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Default_Page_URL"="http://www.google.com"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Default_Page_URL"="http://www.google.com"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{A1DED023-5C94-472A-9818-532B935C17E1} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13415"
==== Reset Google Chrome ======================
Nothing found to reset
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoobzoYouTubeAccelerator deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=28 folders=19 19551480 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\JELNKO~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on ne 28.09.2014 at 9:38:39,11 ======================
Zoek.exe v5.0.0.0 Updated 27-09-2014
Tool run by Jelˇnkovi on ne 28.09.2014 at 9:18:15,77.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\JELNKO~1\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
28.9.2014 9:19:43 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
Added to C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
user.js not found
---- Lines a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831 removed from prefs.js ----
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.coma0cd156
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.coma0cd156
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncdb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncdb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncin
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.0cd1569197354ecf9be03@d3ee3bc4210848f7b5a58324f064f.comasyncin
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.active", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.addressbar", "NA");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.addressbarenhanced", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.asyncdb.was_copied", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.asyncinternaldb.was_copied", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.backgroundver", 1);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.certdomaininstaller", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallationTime.value", "%221410889102%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22002128
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.load_balancer.expiration", "Thu Sep 25 2014 19:51:11 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.load_balancer.value", "%22%7B%20%5C%22Status%5C%22%3A%2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.previous_page.expiration", "Fri Feb 01 2030 00:00:00 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.previous_page.value", "%22http%3A//www.seznam.cz/%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.user_id.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.cookie.user_id.value", "%22148833220e32d9175fcfed266bf0b179%22
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.description", "Lights out for YouTube");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.domain", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.enablesearch", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.homepage", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.changeprevious", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.iframe", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.InstallationThankYouPage", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.InstallationTime", 1410889102);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__defualt_browser__.value", "%22ff%22");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__blacklist_domain.expiration", "Fri Feb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules.expiration", "Fri Feb 01 2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules.value", "%5B%7B%22rules%22
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules_verion.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__global_rules_verion.value", "6");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_daily_visit.expiration", "Fri Sep
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_daily_visit.value", "1411645871064
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_impression_time.expiration", "Fri
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__last_impression_time.value", "141164598
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules.expiration", "Fri Feb 0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules_verion.expiration", "Fr
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__marketing_rules_verion.value", "52");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pages_visited_count.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pages_visited_count.value", "9");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_19.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_19.8.2014.value", "23");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_20.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_20.8.2014.value", "20");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_21.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_21.8.2014.value", "10");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_22.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_22.8.2014.value", "3");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_23.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_23.8.2014.value", "13");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_24.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_24.8.2014.value", "11");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_25.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_25.8.2014.value", "10");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_26.8.2014.expiration", "
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__pagevies_count_26.8.2014.value", "13");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today.expiration", "F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today.value", "1");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today_siteunder.expir
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__total_impressions_today_siteunder.value
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__verions_data.expiration", "Thu Sep 25 2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.__ICM_LITE__verions_data.value", "%7B%22global_rule
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb._installer_additional_info.expiration", "Fri Feb 01
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb._installer_additional_info.value", "%7B%22asw%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GM
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%2
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%2200
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.InstallerUserIdentifiersCache.value", "%7B%22instal
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledUrls.expiration", "Fri F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledWithHash.expiration", "F
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_bundledWithHash.value", "null")
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_notBundledArr_.expiration", "Fr
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D"
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_regBundledWithSoftware.expirati
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.monetization_plugin_regBundledWithSoftware.value",
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:0
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_appVer.value", "47");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_nextCheck.expiration", "Thu Sep 25 2014 1
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.lastDailyReport", "1411645866325");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.lastUpdate", "1411645852113");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.manifesturl", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.name", "CinPlus-2.4c");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.newtab", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.opensearch", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.pluginsurl", "http://js.newclientstaticsrv.com/plugin/apps/638
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.pluginsversion", 40);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.publisher", "Cinema Plus");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.searchstatus", 0);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.setnewtab", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.thankyou", "");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.updateinterval", 360);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.63831.ver", 47);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.apps", "63831");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.cid", 63831);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.firstrun", false);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.hadappinstalled", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.installationdate", 1410950374);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.modetype", "production");
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.reportInstall", true);
user_pref("extensions.a0cd1569197354ecf9be03d3ee3bc4210848f7b5a58324f064fcom63831.statsDailyCounter", 10);
---- Lines awarnerrobertshotmailcom61915 removed from prefs.js ----
user_pref("extensions.awarnerrobertshotmailcom61915.61915.active", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.addressbar", "NA");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.addressbarenhanced", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.asyncdb.was_copied", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.asyncinternaldb.was_copied", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.backgroundver", 1);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.certdomaininstaller", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallationTime.value", "%221411656679%22");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A%220%22%2
user_pref("extensions.awarnerrobertshotmailcom61915.61915.description", ".");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.domain", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.enablesearch", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.homepage", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.changeprevious", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.iframe", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.InstallationThankYouPage", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.InstallationTime", 1411656679);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.__defualt_browser__.value", "%22ch%22");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb._installer_additional_info.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb._installer_additional_info.value", "%7B%22asw%22%3A%5B0%2C5%2C536879104%5D%2C%22b
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%22installer_bic%22%3A%2263
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%2263C04260A4E7401B9100AB8
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A%220%
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParamsCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerParamsCache.value", "%7B%22source_id%22%3A%22000805%22%2C%22sub_id%22%3A
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerUserIdentifiersCache.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.InstallerUserIdentifiersCache.value", "%7B%22installer_bic%22%3A%2263C04260A4E740
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledUrls.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100")
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledWithHash.expiration", "Fri Feb 01 2030 00:00:00 GMT+01
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledWithHash.value", "null");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_notBundledArr_.expiration", "Fri Feb 01 2030 00:00:00 GMT+010
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_notBundledArr_.value", "%5B%5D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_regBundledWithSoftware.expiration", "Fri Feb 01 2030 00:00:00
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_regBundledWithSoftware.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_appVer.value", "33");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_lastVersion.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_nextCheck.expiration", "Tue Jan 01 2002 06:04:54 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_remote_resources.expiration", "Fri Feb 01 2030 00:00:00 GMT+0100");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.Resources_remote_resources.value", "%7B%22remoteId%22%3A0%7D");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.lastDailyReport", "1009839889604");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.lastUpdate", "1009839889321");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.manifesturl", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.name", "Senses");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.newtab", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.opensearch", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.pluginsurl", "http://js.newclientstaticsrv.com/plugin ... ugins.json"
user_pref("extensions.awarnerrobertshotmailcom61915.61915.pluginsversion", 29);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.publisher", "Object Browser");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.searchstatus", 0);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.setnewtab", false);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.thankyou", "");
user_pref("extensions.awarnerrobertshotmailcom61915.61915.updateinterval", 360);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.ver", 33);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncdb_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncinternaldb_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comasyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comawarnerrobertshotmailcom61915_dbWasSet", true);
user_pref("extensions.awarnerrobertshotmailcom61915.61915.warnerroberts@hotmail.comawarnerrobertshotmailcom61915_dbWasSet_FF25_FIX", true);
user_pref("extensions.awarnerrobertshotmailcom61915.apps", "61915");
user_pref("extensions.awarnerrobertshotmailcom61915.bic", "148833220e32d9175fcfed266bf0b179");
user_pref("extensions.awarnerrobertshotmailcom61915.cid", 61915);
user_pref("extensions.awarnerrobertshotmailcom61915.firstrun", false);
user_pref("extensions.awarnerrobertshotmailcom61915.hadappinstalled", true);
user_pref("extensions.awarnerrobertshotmailcom61915.installationdate", 1009839886);
user_pref("extensions.awarnerrobertshotmailcom61915.modetype", "production");
user_pref("extensions.awarnerrobertshotmailcom61915.reportInstall", true);
user_pref("extensions.awarnerrobertshotmailcom61915.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----
prefs_28.09.2014_0931_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~3\HirezPipeError.txt deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\Tasks\0464758d-0fde-4a9d-bab3-cf5e9bb09d42-5_user.job deleted
C:\Windows\Tasks\c35b2cdd-fb59-43cc-8ac4-c15bc81e5094-5_user.job deleted
C:\Windows\tasks\9fd63f7b-0ac4-4ff5-8cf7-a189b34c18ec.job deleted
C:\windows\SysNative\Tasks\YTAUpdate deleted
C:\windows\SysNative\tasks\Installer_shopperpro deleted
C:\windows\SysNative\tasks\GPUP deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\SysWOW64\AniGIF.ocx deleted
C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\extensions\firefox@mega.co.nz.xpi deleted
C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\jetpack deleted
C:\Users\JELNKO~1\Desktop\Continue installation - GotClipDownloader Installation.lnk deleted
"C:\Users\JELNKO~1\AppData\Local\LumaEmu" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [15.08.2014 14:11]
==== Firefox Extensions ======================
ProfilePath: C:\Users\JELNKO~1\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- AdBlock for Firefox - %ProfilePath%\extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[15.08.2014 14:11]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Page"="http://www.google.com"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Default_Page_URL"="http://www.google.com"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Default_Page_URL"="http://www.google.com"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{A1DED023-5C94-472A-9818-532B935C17E1} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_13415"
==== Reset Google Chrome ======================
Nothing found to reset
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoobzoYouTubeAccelerator deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=28 folders=19 19551480 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\JELNKO~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on ne 28.09.2014 at 9:38:39,11 ======================
Re: Problem se spamem a internetem
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-09-2014
Ran by Jelínkovi (administrator) on JELÍNKOVI-PC on 28-09-2014 11:35:43
Running from C:\Users\Jelínkovi\Desktop
Loaded Profile: Jelínkovi (Available profiles: Jelínkovi)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
() C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2014-04-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-15] (AVAST Software)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [868352 2006-12-18] (Analog Devices, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-12-06] (AMD)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Game Fire] => C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [44032 2011-12-02] (Smart PC Utilities, Ltd.)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\MountPoints2: {7c89468e-bf9e-11e3-bef1-001a9234e086} - E:\Autorun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-03-07] (Microsoft Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {A1DED023-5C94-472A-9818-532B935C17E1} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Senses -> {11111111-1111-1111-1111-110611191115} -> C:\Program Files (x86)\Senses\Senses-bho64.dll No File
BHO: No Name -> {11111111-1111-1111-1111-110611381131} -> No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 10.10.5.254
FireFox:
========
FF ProfilePath: C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jelínkovi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll No File
FF SearchPlugin: C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF Extension: AdBlock for Firefox - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2014-09-20]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-05]
Chrome:
=======
CHR Profile: C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-04]
CHR Extension: (No Name) - C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\plimopelmdneikoknbgpopffpbmlhgpa [2014-09-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-15]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-15] (AVAST Software)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 3xHybr64; C:\Windows\System32\DRIVERS\3xHybr64.sys [873216 2007-04-20] (Philips Semiconductors GmbH)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-15] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-15] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-15] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-15] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-15] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-04-09] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-09] (Disc Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-04-09] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 [X]
S3 X6va027; \??\C:\Windows\SysWOW64\Drivers\X6va027 [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-28 11:35 - 2014-09-28 11:36 - 00010618 _____ () C:\Users\Jelínkovi\Desktop\FRST.txt
2014-09-28 11:35 - 2014-09-28 11:35 - 00000000 ____D () C:\FRST
2014-09-28 11:33 - 2014-09-28 11:33 - 00112640 _____ (forum.viry.cz) C:\Users\Jelínkovi\Desktop\FRSTLauncher.exe
2014-09-28 11:31 - 2014-09-28 11:31 - 02108928 _____ (Farbar) C:\Users\Jelínkovi\Desktop\FRST64.exe
2014-09-28 09:35 - 2014-09-28 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-28 09:19 - 2014-09-28 09:38 - 00035767 _____ () C:\zoek-results.log
2014-09-28 09:18 - 2014-09-28 09:32 - 00000000 ____D () C:\zoek_backup
2014-09-28 09:16 - 2014-09-28 09:16 - 04256073 _____ () C:\Users\Jelínkovi\Downloads\zoek.rar
2014-09-28 09:15 - 2014-09-28 09:15 - 01290752 _____ () C:\Users\Jelínkovi\Desktop\zoek.exe
2014-09-27 19:21 - 2014-09-27 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-09-27 19:21 - 2014-09-27 19:21 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-09-27 19:19 - 2014-09-27 19:19 - 16995328 _____ () C:\Users\Jelínkovi\Downloads\mumble-1.2.8.msi
2014-09-27 19:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-27 18:59 - 2014-09-27 19:08 - 00000000 ____D () C:\AdwCleaner
2014-09-27 18:58 - 2014-09-27 18:58 - 00009791 _____ () C:\Users\Jelínkovi\Desktop\JRT.txt
2014-09-27 18:52 - 2014-09-27 18:52 - 00000000 ____D () C:\Windows\ERUNT
2014-09-27 18:51 - 2014-09-27 18:51 - 01699276 _____ (Thisisu) C:\Users\Jelínkovi\Desktop\JRT.exe
2014-09-27 18:51 - 2014-09-27 18:51 - 01373475 _____ () C:\Users\Jelínkovi\Desktop\adwcleaner_3.310.exe
2014-09-27 18:47 - 2014-09-27 18:47 - 00003170 _____ () C:\Windows\System32\Tasks\{5BACE983-405A-476D-A56D-94B3A7FCC4DB}
2014-09-27 18:33 - 2014-09-27 18:33 - 01107968 _____ () C:\Users\Jelínkovi\Downloads\RSIT.exe
2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\rsit
2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\Program Files (x86)\trend micro
2014-09-25 17:02 - 2014-09-25 17:05 - 00578602 _____ () C:\spyhunter.fix
2014-09-25 16:52 - 2014-09-27 18:55 - 00000000 ____D () C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2014-09-25 16:52 - 2014-09-25 16:52 - 01508248 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\AIHGXB.exe
2014-09-25 16:52 - 2014-09-25 16:52 - 00001354 _____ () C:\Windows\Tasks\AIHGXB.job
2014-09-25 16:51 - 2014-09-25 16:51 - 01955736 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF.exe
2014-09-25 16:51 - 2014-09-25 16:51 - 00001702 _____ () C:\Windows\Tasks\KEAYWJIF.job
2014-09-25 16:39 - 2014-09-25 16:39 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Local\CrashRpt
2014-09-25 16:20 - 2014-09-25 16:20 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\spyhunt
2014-09-25 13:05 - 2014-09-25 13:05 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
2014-09-25 13:03 - 2014-09-25 16:53 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-25 07:13 - 2014-09-25 07:13 - 00000000 _____ () C:\autoexec.bat
2014-09-25 07:12 - 2014-09-25 16:43 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-25 06:50 - 2013-06-27 10:59 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\firefox
2014-09-24 06:57 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 06:57 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-22 18:21 - 2014-09-22 18:29 - 115046211 _____ () C:\Users\Jelínkovi\Downloads\[Yakudzuke]Akame_ga_Kill_12[720p_CZ][DA25426B].mp4
2014-09-22 13:09 - 2014-09-22 13:20 - 83523323 _____ () C:\Users\Jelínkovi\Downloads\The-Sims-2-cz---základní-hra-by-Hunys.iso
2014-09-22 13:07 - 2014-09-22 13:07 - 00433317 _____ () C:\Users\Jelínkovi\Downloads\The-sims-3-cz-plná-verze.rar
2014-09-17 19:40 - 2014-09-27 18:37 - 00070144 _____ () C:\Windows\SysWOW64\tasks.dll
2014-09-17 13:04 - 2014-09-17 13:04 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Ubisoft
2014-09-17 13:04 - 2014-09-17 13:04 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-09-17 13:00 - 2008-03-26 10:47 - 25667160 _____ (Ubisoft) C:\Users\Jelínkovi\Desktop\AssassinsCreed_Dx10 (2).exe
2014-09-17 12:59 - 2008-03-26 10:46 - 26150480 _____ (Ubisoft) C:\Users\Jelínkovi\Desktop\AssassinsCreed_Dx9 (2).exe
2014-09-17 12:51 - 2014-09-17 13:04 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\Ssassins creed
2014-09-16 19:40 - 2014-09-17 05:44 - 1208140290 _____ () C:\Users\Jelínkovi\Downloads\Assassins-Creed-(1)-(cz-tit,-dabing,plna-hra)-zaitoshi.rar
2014-09-16 19:39 - 2014-09-16 19:39 - 01524120 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\YJVIWV.exe
2014-09-16 19:39 - 2014-09-16 19:39 - 00001354 _____ () C:\Windows\Tasks\YJVIWV.job
2014-09-16 19:38 - 2014-09-16 19:38 - 01972632 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\QWMS.exe
2014-09-16 19:38 - 2014-09-16 19:38 - 00001350 _____ () C:\Windows\Tasks\QWMS.job
2014-09-16 17:11 - 2014-09-16 17:11 - 00000222 _____ () C:\Users\Jelínkovi\Desktop\Fistful of Frags.url
2014-09-16 06:30 - 2014-09-16 06:30 - 00000008 _____ () C:\Users\Jelínkovi\Desktop\launcher.conf
2014-09-16 06:30 - 2014-09-16 06:30 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\WTF
2014-09-15 16:30 - 2014-05-15 16:14 - 03191392 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2014-09-15 16:29 - 2014-09-15 16:29 - 00000000 ____D () C:\Program Files\Common Files\INCA Shared
2014-09-15 16:26 - 2014-09-15 16:26 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-09-15 16:26 - 2014-09-15 16:26 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-15 16:17 - 2014-09-15 16:17 - 00000222 _____ () C:\Users\Jelínkovi\Desktop\Dizzel.url
2014-09-15 13:45 - 2006-09-09 12:01 - 00000081 _____ () C:\Users\Jelínkovi\Desktop\SUPPORT Slovenciny.Com.url
2014-09-15 13:45 - 2006-09-09 12:00 - 00000079 _____ () C:\Users\Jelínkovi\Desktop\SPONZOR - megahry.eu.url
2014-09-15 13:45 - 2006-09-09 12:00 - 00000073 _____ () C:\Users\Jelínkovi\Desktop\AUTOR www.liv.sk.url
2014-09-15 13:45 - 2006-08-20 20:08 - 05994272 _____ (CivCity Rím SK tím) C:\Users\Jelínkovi\Desktop\CivCity-Rím_SK.exe
2014-09-15 13:42 - 2014-09-15 13:42 - 00003220 _____ () C:\Windows\System32\Tasks\{5945E194-5F67-4DC5-9955-985779A1F2E8}
2014-09-15 13:41 - 2012-07-22 18:10 - 06027432 _____ () C:\Users\Jelínkovi\Desktop\civcity_rim_sk.zip
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Documents\CivCity Rím
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\ui
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\i18n
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\help
2014-09-15 13:28 - 2014-09-15 13:28 - 00001121 _____ () C:\Users\Jelínkovi\Desktop\CivCity Rome – zástupce.lnk
2014-09-15 13:18 - 2014-09-15 13:18 - 00000000 ____D () C:\ProgramData\Firefly Studios
2014-09-15 13:17 - 2014-09-15 13:24 - 00000000 ____D () C:\Users\Jelínkovi\Documents\CivCity Rome
2014-09-15 13:14 - 2014-09-15 13:41 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\city of rome
2014-09-15 12:59 - 2014-09-15 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
2014-09-15 11:23 - 2014-09-15 12:50 - 1549422592 _____ () C:\Users\Jelínkovi\Downloads\CivCity-Rome.iso
2014-09-15 11:07 - 2014-09-15 13:27 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\CivCity-Rome
2014-09-15 07:47 - 2014-09-15 07:47 - 00001201 _____ () C:\Users\Public\Desktop\Island Tribe.lnk
2014-09-15 07:46 - 2014-09-15 07:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Island Tribe
2014-09-15 07:46 - 2014-09-15 07:46 - 00000000 ____D () C:\Program Files (x86)\LeeGT-Games
2014-09-15 07:44 - 2014-09-15 07:44 - 00001169 _____ () C:\Users\Public\Desktop\MORE DOWNLOADS.lnk
2014-09-15 07:44 - 2014-09-15 07:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISLAND TRIBE 2
2014-09-15 07:43 - 2014-09-17 12:42 - 00000000 ____D () C:\Program Files (x86)\ISLAND TRIBE 2
2014-09-15 07:35 - 2014-09-15 07:39 - 65994555 _____ (Oberon Media Inc.) C:\Users\Jelínkovi\Downloads\island_tribe_48512154-setup-(1).exe
2014-09-15 07:16 - 2014-09-15 07:21 - 00000000 ____D () C:\hry
2014-09-14 07:25 - 2014-09-14 07:25 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\SessionStatistic_detailed_loca_92
2014-09-11 18:25 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 18:25 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 18:25 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 18:25 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 18:25 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 18:25 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 18:25 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 18:25 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 18:25 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 18:25 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 18:25 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 18:25 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 18:25 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 18:25 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 18:25 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 18:25 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 18:25 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 18:25 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 18:25 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 18:25 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 18:25 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 18:25 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 18:25 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 18:25 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 18:25 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 18:25 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 18:25 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 18:25 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 18:25 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 18:25 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 18:25 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 18:25 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 18:25 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 18:25 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 18:25 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 18:25 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 18:25 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 18:25 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 18:25 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 18:25 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 18:25 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 18:25 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 18:25 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 18:25 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 18:25 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 18:25 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 18:25 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 18:25 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 18:25 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 18:25 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 18:22 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 18:22 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 06:40 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 06:40 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 06:40 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 06:40 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 06:39 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-11 06:39 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-11 06:39 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 06:39 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 06:39 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 06:39 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 06:39 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 14:24 - 2014-09-10 14:24 - 00002716 _____ () C:\Users\Jelínkovi\Desktop\Play Jurassic Park Operation Genesis.lnk
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Universal Interactive
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Interactive
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\Program Files (x86)\Universal Interactive
2014-09-10 14:14 - 2014-09-10 14:14 - 00000000 ____D () C:\Program Files\Universal Interactive
2014-09-09 15:55 - 2014-09-09 15:58 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Tibia
2014-09-09 15:54 - 2014-09-09 15:54 - 00000978 _____ () C:\Users\Public\Desktop\Tibia.lnk
2014-09-09 15:54 - 2014-09-09 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tibia
2014-09-09 15:54 - 2014-09-09 15:54 - 00000000 ____D () C:\Program Files (x86)\Tibia
2014-09-09 15:52 - 2014-09-09 15:53 - 40566505 _____ (CipSoft GmbH ) C:\Users\Jelínkovi\Downloads\tibia1054.exe
2014-09-08 17:50 - 2014-09-08 17:51 - 19403318 _____ () C:\Users\Jelínkovi\Downloads\The-Escapists-v0.753.rar
2014-09-08 16:11 - 2014-09-08 16:11 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\PlayFirst
2014-09-08 16:11 - 2014-09-08 16:11 - 00000000 ____D () C:\ProgramData\PlayFirst
2014-09-08 16:10 - 2014-09-08 16:10 - 00000000 ____D () C:\Wandering-Willows
2014-09-08 16:07 - 2014-09-08 16:09 - 27334543 _____ () C:\Users\Jelínkovi\Downloads\Wandering-Willows-instal.zip
2014-09-08 07:17 - 2014-09-25 16:33 - 00001081 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-09-08 07:17 - 2014-09-08 07:40 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\vlc
2014-09-08 07:16 - 2014-09-25 16:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-09-08 07:16 - 2014-09-08 07:16 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-09-08 07:15 - 2014-09-08 07:16 - 31206605 _____ () C:\Users\Jelínkovi\Downloads\vlc-setup.exe
2014-09-08 07:10 - 2014-09-08 07:11 - 39284090 _____ () C:\Users\Jelínkovi\Desktop\kmplayer-setup.exe
2014-09-07 11:40 - 2014-09-07 11:47 - 00006633 _____ () C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
2014-09-05 17:16 - 2014-09-05 17:16 - 00000219 _____ () C:\Users\Jelínkovi\Desktop\Dota 2.url
2014-09-03 12:08 - 2014-09-03 12:12 - 00000000 ____D () C:\Users\Public\Documents\s.t.a.l.k.e.r. - call of pripyat
2014-09-03 12:08 - 2014-09-03 12:08 - 00001403 _____ () C:\Users\Jelínkovi\Desktop\S.T.A.L.K.E.R. - Call of Pripyat.lnk
2014-09-03 12:08 - 2014-09-03 12:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
2014-09-03 11:59 - 2014-09-03 11:59 - 00000000 ____D () C:\Program Files (x86)\bitComposer Games
2014-09-03 07:34 - 2014-09-03 10:55 - 3583712841 _____ () C:\Users\Jelínkovi\Downloads\S.T.A.L.K.E.R.---Call-of-Pripyat-+-čeština.rar
2014-09-03 06:02 - 2014-09-03 06:03 - 00000000 ____D () C:\Users\Jelínkovi\Documents\Cross Fire
2014-09-03 06:02 - 2014-09-03 06:02 - 00000000 ____D () C:\CFLog
2014-09-03 06:00 - 2014-09-03 06:00 - 00000839 _____ () C:\Users\Jelínkovi\Desktop\Crossfire Europe.lnk
2014-09-03 06:00 - 2014-09-03 06:00 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2014-09-03 06:00 - 2014-09-03 06:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2014-09-03 05:50 - 2014-09-03 05:50 - 00000000 ____D () C:\SG Interactive
2014-09-03 05:39 - 2014-09-03 05:39 - 00000181 _____ () C:\console.log
2014-09-03 05:39 - 2014-09-03 05:39 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\CrossFire EU
2014-09-03 05:38 - 2014-09-03 05:38 - 02156048 _____ (Reloaded Technologies) C:\Users\Jelínkovi\Downloads\Crossfire_downloader.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Jelínkovi\AppData\Roaming\YJVIWV
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Jelínkovi\AppData\Roaming\AIHGXB
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Jelínkovi\AppData\Roaming\QWMS
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-28 10:49 - 2014-03-05 20:01 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-28 10:20 - 2014-03-05 19:15 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Mumble
2014-09-28 09:44 - 2009-07-14 06:45 - 00022656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-28 09:44 - 2009-07-14 06:45 - 00022656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-28 09:43 - 2014-05-15 12:33 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz
2014-09-28 09:43 - 2009-07-14 17:18 - 00668542 _____ () C:\Windows\system32\perfh005.dat
2014-09-28 09:43 - 2009-07-14 17:18 - 00141202 _____ () C:\Windows\system32\perfc005.dat
2014-09-28 09:43 - 2009-07-14 07:13 - 01583226 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-28 09:40 - 2014-03-05 18:50 - 01654688 _____ () C:\Windows\WindowsUpdate.log
2014-09-28 09:37 - 2014-07-04 17:39 - 00010905 _____ () C:\Windows\setupact.log
2014-09-28 09:37 - 2014-07-04 17:39 - 00010094 _____ () C:\Windows\PFRO.log
2014-09-28 09:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-27 19:07 - 2014-05-15 12:34 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-27 18:49 - 2014-03-05 18:59 - 00001378 _____ () C:\Users\Jelínkovi\Desktop\Internet Explorer.lnk
2014-09-27 18:49 - 2002-03-24 08:27 - 00001174 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-27 18:49 - 2002-03-24 08:27 - 00001162 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-27 18:45 - 2014-03-05 19:32 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-25 16:50 - 2014-05-15 12:35 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Skype
2014-09-25 08:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-23 17:32 - 2014-07-05 10:42 - 00000000 ____D () C:\Program Files (x86)\Guild Wars 2
2014-09-23 17:01 - 2014-07-21 08:08 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-22 18:37 - 2014-08-23 13:16 - 00000750 _____ () C:\Users\Jelínkovi\Desktop\serial.txt
2014-09-22 18:37 - 2014-08-23 13:16 - 00000002 _____ () C:\Users\Jelínkovi\Desktop\myFile.txt
2014-09-22 18:00 - 2014-03-05 19:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-22 17:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-20 18:40 - 2014-07-05 10:38 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Guild Wars 2
2014-09-18 17:59 - 2014-06-11 14:38 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-09-18 17:59 - 2014-06-11 14:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-18 17:59 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Skype
2014-09-17 13:02 - 2014-07-21 08:54 - 00437436 _____ () C:\Windows\DirectX.log
2014-09-17 13:00 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-09-17 12:52 - 2014-03-05 20:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-09-17 12:42 - 2014-08-28 10:06 - 00000000 ____D () C:\Program Files (x86)\Game_Maker8
2014-09-17 12:42 - 2014-08-26 14:29 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\Stranger
2014-09-17 12:42 - 2014-06-22 16:00 - 00000000 ____D () C:\Program Files (x86)\Mount&Blade
2014-09-17 12:42 - 2014-04-09 07:27 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-09-17 12:42 - 2014-03-05 20:27 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-09-15 09:06 - 2014-03-05 19:58 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-11 18:24 - 2014-03-05 19:22 - 01557940 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 18:21 - 2014-04-30 23:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-10 18:49 - 2014-03-05 20:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 18:49 - 2014-03-05 20:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-10 18:49 - 2014-03-05 20:01 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 14:25 - 2014-03-07 15:55 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-09-10 14:15 - 2014-04-09 07:27 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\DAEMON Tools Lite
2014-09-04 17:22 - 2014-04-09 12:59 - 00000000 ____D () C:\Users\Jelínkovi\Documents\gothic3
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-28 10:37
==================== End Of Log ============================
Ran by Jelínkovi (administrator) on JELÍNKOVI-PC on 28-09-2014 11:35:43
Running from C:\Users\Jelínkovi\Desktop
Loaded Profile: Jelínkovi (Available profiles: Jelínkovi)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
() C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2014-04-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-15] (AVAST Software)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [868352 2006-12-18] (Analog Devices, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-12-06] (AMD)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Game Fire] => C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [44032 2011-12-02] (Smart PC Utilities, Ltd.)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\MountPoints2: {7c89468e-bf9e-11e3-bef1-001a9234e086} - E:\Autorun.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-03-07] (Microsoft Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {A1DED023-5C94-472A-9818-532B935C17E1} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Senses -> {11111111-1111-1111-1111-110611191115} -> C:\Program Files (x86)\Senses\Senses-bho64.dll No File
BHO: No Name -> {11111111-1111-1111-1111-110611381131} -> No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 10.10.5.254
FireFox:
========
FF ProfilePath: C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Jelínkovi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll No File
FF SearchPlugin: C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\searchplugins\seznam-avast.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF Extension: AdBlock for Firefox - C:\Users\Jelínkovi\AppData\Roaming\Mozilla\Firefox\Profiles\n8ca5hhb.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2014-09-20]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-05]
Chrome:
=======
CHR Profile: C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-04]
CHR Extension: (No Name) - C:\Users\Jelínkovi\AppData\Local\Google\Chrome\User Data\Default\Extensions\plimopelmdneikoknbgpopffpbmlhgpa [2014-09-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-15]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-15] (AVAST Software)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3191392 2014-05-15] (INCA Internet Co., Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 3xHybr64; C:\Windows\System32\DRIVERS\3xHybr64.sys [873216 2007-04-20] (Philips Semiconductors GmbH)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-15] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-15] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-15] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-15] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-15] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2014-04-09] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-09] (Disc Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2014-04-09] ()
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 [X]
S3 X6va027; \??\C:\Windows\SysWOW64\Drivers\X6va027 [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-28 11:35 - 2014-09-28 11:36 - 00010618 _____ () C:\Users\Jelínkovi\Desktop\FRST.txt
2014-09-28 11:35 - 2014-09-28 11:35 - 00000000 ____D () C:\FRST
2014-09-28 11:33 - 2014-09-28 11:33 - 00112640 _____ (forum.viry.cz) C:\Users\Jelínkovi\Desktop\FRSTLauncher.exe
2014-09-28 11:31 - 2014-09-28 11:31 - 02108928 _____ (Farbar) C:\Users\Jelínkovi\Desktop\FRST64.exe
2014-09-28 09:35 - 2014-09-28 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-28 09:19 - 2014-09-28 09:38 - 00035767 _____ () C:\zoek-results.log
2014-09-28 09:18 - 2014-09-28 09:32 - 00000000 ____D () C:\zoek_backup
2014-09-28 09:16 - 2014-09-28 09:16 - 04256073 _____ () C:\Users\Jelínkovi\Downloads\zoek.rar
2014-09-28 09:15 - 2014-09-28 09:15 - 01290752 _____ () C:\Users\Jelínkovi\Desktop\zoek.exe
2014-09-27 19:21 - 2014-09-27 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-09-27 19:21 - 2014-09-27 19:21 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-09-27 19:19 - 2014-09-27 19:19 - 16995328 _____ () C:\Users\Jelínkovi\Downloads\mumble-1.2.8.msi
2014-09-27 19:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-27 18:59 - 2014-09-27 19:08 - 00000000 ____D () C:\AdwCleaner
2014-09-27 18:58 - 2014-09-27 18:58 - 00009791 _____ () C:\Users\Jelínkovi\Desktop\JRT.txt
2014-09-27 18:52 - 2014-09-27 18:52 - 00000000 ____D () C:\Windows\ERUNT
2014-09-27 18:51 - 2014-09-27 18:51 - 01699276 _____ (Thisisu) C:\Users\Jelínkovi\Desktop\JRT.exe
2014-09-27 18:51 - 2014-09-27 18:51 - 01373475 _____ () C:\Users\Jelínkovi\Desktop\adwcleaner_3.310.exe
2014-09-27 18:47 - 2014-09-27 18:47 - 00003170 _____ () C:\Windows\System32\Tasks\{5BACE983-405A-476D-A56D-94B3A7FCC4DB}
2014-09-27 18:33 - 2014-09-27 18:33 - 01107968 _____ () C:\Users\Jelínkovi\Downloads\RSIT.exe
2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\rsit
2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\Program Files (x86)\trend micro
2014-09-25 17:02 - 2014-09-25 17:05 - 00578602 _____ () C:\spyhunter.fix
2014-09-25 16:52 - 2014-09-27 18:55 - 00000000 ____D () C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2014-09-25 16:52 - 2014-09-25 16:52 - 01508248 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\AIHGXB.exe
2014-09-25 16:52 - 2014-09-25 16:52 - 00001354 _____ () C:\Windows\Tasks\AIHGXB.job
2014-09-25 16:51 - 2014-09-25 16:51 - 01955736 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF.exe
2014-09-25 16:51 - 2014-09-25 16:51 - 00001702 _____ () C:\Windows\Tasks\KEAYWJIF.job
2014-09-25 16:39 - 2014-09-25 16:39 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Local\CrashRpt
2014-09-25 16:20 - 2014-09-25 16:20 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\spyhunt
2014-09-25 13:05 - 2014-09-25 13:05 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group
2014-09-25 13:03 - 2014-09-25 16:53 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-09-25 07:13 - 2014-09-25 07:13 - 00000000 _____ () C:\autoexec.bat
2014-09-25 07:12 - 2014-09-25 16:43 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-09-25 06:50 - 2013-06-27 10:59 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\firefox
2014-09-24 06:57 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 06:57 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-22 18:21 - 2014-09-22 18:29 - 115046211 _____ () C:\Users\Jelínkovi\Downloads\[Yakudzuke]Akame_ga_Kill_12[720p_CZ][DA25426B].mp4
2014-09-22 13:09 - 2014-09-22 13:20 - 83523323 _____ () C:\Users\Jelínkovi\Downloads\The-Sims-2-cz---základní-hra-by-Hunys.iso
2014-09-22 13:07 - 2014-09-22 13:07 - 00433317 _____ () C:\Users\Jelínkovi\Downloads\The-sims-3-cz-plná-verze.rar
2014-09-17 19:40 - 2014-09-27 18:37 - 00070144 _____ () C:\Windows\SysWOW64\tasks.dll
2014-09-17 13:04 - 2014-09-17 13:04 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Ubisoft
2014-09-17 13:04 - 2014-09-17 13:04 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-09-17 13:00 - 2008-03-26 10:47 - 25667160 _____ (Ubisoft) C:\Users\Jelínkovi\Desktop\AssassinsCreed_Dx10 (2).exe
2014-09-17 12:59 - 2008-03-26 10:46 - 26150480 _____ (Ubisoft) C:\Users\Jelínkovi\Desktop\AssassinsCreed_Dx9 (2).exe
2014-09-17 12:51 - 2014-09-17 13:04 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\Ssassins creed
2014-09-16 19:40 - 2014-09-17 05:44 - 1208140290 _____ () C:\Users\Jelínkovi\Downloads\Assassins-Creed-(1)-(cz-tit,-dabing,plna-hra)-zaitoshi.rar
2014-09-16 19:39 - 2014-09-16 19:39 - 01524120 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\YJVIWV.exe
2014-09-16 19:39 - 2014-09-16 19:39 - 00001354 _____ () C:\Windows\Tasks\YJVIWV.job
2014-09-16 19:38 - 2014-09-16 19:38 - 01972632 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\QWMS.exe
2014-09-16 19:38 - 2014-09-16 19:38 - 00001350 _____ () C:\Windows\Tasks\QWMS.job
2014-09-16 17:11 - 2014-09-16 17:11 - 00000222 _____ () C:\Users\Jelínkovi\Desktop\Fistful of Frags.url
2014-09-16 06:30 - 2014-09-16 06:30 - 00000008 _____ () C:\Users\Jelínkovi\Desktop\launcher.conf
2014-09-16 06:30 - 2014-09-16 06:30 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\WTF
2014-09-15 16:30 - 2014-05-15 16:14 - 03191392 _____ (INCA Internet Co., Ltd.) C:\Windows\SysWOW64\GameMon.des
2014-09-15 16:29 - 2014-09-15 16:29 - 00000000 ____D () C:\Program Files\Common Files\INCA Shared
2014-09-15 16:26 - 2014-09-15 16:26 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-09-15 16:26 - 2014-09-15 16:26 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-09-15 16:17 - 2014-09-15 16:17 - 00000222 _____ () C:\Users\Jelínkovi\Desktop\Dizzel.url
2014-09-15 13:45 - 2006-09-09 12:01 - 00000081 _____ () C:\Users\Jelínkovi\Desktop\SUPPORT Slovenciny.Com.url
2014-09-15 13:45 - 2006-09-09 12:00 - 00000079 _____ () C:\Users\Jelínkovi\Desktop\SPONZOR - megahry.eu.url
2014-09-15 13:45 - 2006-09-09 12:00 - 00000073 _____ () C:\Users\Jelínkovi\Desktop\AUTOR www.liv.sk.url
2014-09-15 13:45 - 2006-08-20 20:08 - 05994272 _____ (CivCity Rím SK tím) C:\Users\Jelínkovi\Desktop\CivCity-Rím_SK.exe
2014-09-15 13:42 - 2014-09-15 13:42 - 00003220 _____ () C:\Windows\System32\Tasks\{5945E194-5F67-4DC5-9955-985779A1F2E8}
2014-09-15 13:41 - 2012-07-22 18:10 - 06027432 _____ () C:\Users\Jelínkovi\Desktop\civcity_rim_sk.zip
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Documents\CivCity Rím
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\ui
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\i18n
2014-09-15 13:35 - 2014-09-15 13:35 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\help
2014-09-15 13:28 - 2014-09-15 13:28 - 00001121 _____ () C:\Users\Jelínkovi\Desktop\CivCity Rome – zástupce.lnk
2014-09-15 13:18 - 2014-09-15 13:18 - 00000000 ____D () C:\ProgramData\Firefly Studios
2014-09-15 13:17 - 2014-09-15 13:24 - 00000000 ____D () C:\Users\Jelínkovi\Documents\CivCity Rome
2014-09-15 13:14 - 2014-09-15 13:41 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\city of rome
2014-09-15 12:59 - 2014-09-15 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
2014-09-15 11:23 - 2014-09-15 12:50 - 1549422592 _____ () C:\Users\Jelínkovi\Downloads\CivCity-Rome.iso
2014-09-15 11:07 - 2014-09-15 13:27 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\CivCity-Rome
2014-09-15 07:47 - 2014-09-15 07:47 - 00001201 _____ () C:\Users\Public\Desktop\Island Tribe.lnk
2014-09-15 07:46 - 2014-09-15 07:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Island Tribe
2014-09-15 07:46 - 2014-09-15 07:46 - 00000000 ____D () C:\Program Files (x86)\LeeGT-Games
2014-09-15 07:44 - 2014-09-15 07:44 - 00001169 _____ () C:\Users\Public\Desktop\MORE DOWNLOADS.lnk
2014-09-15 07:44 - 2014-09-15 07:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISLAND TRIBE 2
2014-09-15 07:43 - 2014-09-17 12:42 - 00000000 ____D () C:\Program Files (x86)\ISLAND TRIBE 2
2014-09-15 07:35 - 2014-09-15 07:39 - 65994555 _____ (Oberon Media Inc.) C:\Users\Jelínkovi\Downloads\island_tribe_48512154-setup-(1).exe
2014-09-15 07:16 - 2014-09-15 07:21 - 00000000 ____D () C:\hry
2014-09-14 07:25 - 2014-09-14 07:25 - 00000000 ____D () C:\Users\Jelínkovi\Downloads\SessionStatistic_detailed_loca_92
2014-09-11 18:25 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 18:25 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 18:25 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 18:25 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 18:25 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 18:25 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 18:25 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 18:25 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 18:25 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 18:25 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 18:25 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 18:25 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 18:25 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 18:25 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 18:25 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 18:25 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 18:25 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 18:25 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 18:25 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 18:25 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 18:25 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 18:25 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 18:25 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 18:25 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 18:25 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 18:25 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 18:25 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 18:25 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 18:25 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 18:25 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 18:25 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 18:25 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 18:25 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 18:25 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 18:25 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 18:25 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 18:25 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 18:25 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 18:25 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 18:25 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 18:25 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 18:25 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 18:25 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 18:25 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 18:25 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 18:25 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 18:25 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 18:25 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 18:25 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 18:25 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 18:25 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 18:25 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 18:22 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 18:22 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 06:40 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 06:40 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 06:40 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 06:40 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 06:39 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-11 06:39 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-11 06:39 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 06:39 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 06:39 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 06:39 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 06:39 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 14:24 - 2014-09-10 14:24 - 00002716 _____ () C:\Users\Jelínkovi\Desktop\Play Jurassic Park Operation Genesis.lnk
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Universal Interactive
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Interactive
2014-09-10 14:24 - 2014-09-10 14:24 - 00000000 ____D () C:\Program Files (x86)\Universal Interactive
2014-09-10 14:14 - 2014-09-10 14:14 - 00000000 ____D () C:\Program Files\Universal Interactive
2014-09-09 15:55 - 2014-09-09 15:58 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Tibia
2014-09-09 15:54 - 2014-09-09 15:54 - 00000978 _____ () C:\Users\Public\Desktop\Tibia.lnk
2014-09-09 15:54 - 2014-09-09 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tibia
2014-09-09 15:54 - 2014-09-09 15:54 - 00000000 ____D () C:\Program Files (x86)\Tibia
2014-09-09 15:52 - 2014-09-09 15:53 - 40566505 _____ (CipSoft GmbH ) C:\Users\Jelínkovi\Downloads\tibia1054.exe
2014-09-08 17:50 - 2014-09-08 17:51 - 19403318 _____ () C:\Users\Jelínkovi\Downloads\The-Escapists-v0.753.rar
2014-09-08 16:11 - 2014-09-08 16:11 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\PlayFirst
2014-09-08 16:11 - 2014-09-08 16:11 - 00000000 ____D () C:\ProgramData\PlayFirst
2014-09-08 16:10 - 2014-09-08 16:10 - 00000000 ____D () C:\Wandering-Willows
2014-09-08 16:07 - 2014-09-08 16:09 - 27334543 _____ () C:\Users\Jelínkovi\Downloads\Wandering-Willows-instal.zip
2014-09-08 07:17 - 2014-09-25 16:33 - 00001081 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-09-08 07:17 - 2014-09-08 07:40 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\vlc
2014-09-08 07:16 - 2014-09-25 16:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-09-08 07:16 - 2014-09-08 07:16 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-09-08 07:15 - 2014-09-08 07:16 - 31206605 _____ () C:\Users\Jelínkovi\Downloads\vlc-setup.exe
2014-09-08 07:10 - 2014-09-08 07:11 - 39284090 _____ () C:\Users\Jelínkovi\Desktop\kmplayer-setup.exe
2014-09-07 11:40 - 2014-09-07 11:47 - 00006633 _____ () C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx
2014-09-05 17:16 - 2014-09-05 17:16 - 00000219 _____ () C:\Users\Jelínkovi\Desktop\Dota 2.url
2014-09-03 12:08 - 2014-09-03 12:12 - 00000000 ____D () C:\Users\Public\Documents\s.t.a.l.k.e.r. - call of pripyat
2014-09-03 12:08 - 2014-09-03 12:08 - 00001403 _____ () C:\Users\Jelínkovi\Desktop\S.T.A.L.K.E.R. - Call of Pripyat.lnk
2014-09-03 12:08 - 2014-09-03 12:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\bitComposer Games
2014-09-03 11:59 - 2014-09-03 11:59 - 00000000 ____D () C:\Program Files (x86)\bitComposer Games
2014-09-03 07:34 - 2014-09-03 10:55 - 3583712841 _____ () C:\Users\Jelínkovi\Downloads\S.T.A.L.K.E.R.---Call-of-Pripyat-+-čeština.rar
2014-09-03 06:02 - 2014-09-03 06:03 - 00000000 ____D () C:\Users\Jelínkovi\Documents\Cross Fire
2014-09-03 06:02 - 2014-09-03 06:02 - 00000000 ____D () C:\CFLog
2014-09-03 06:00 - 2014-09-03 06:00 - 00000839 _____ () C:\Users\Jelínkovi\Desktop\Crossfire Europe.lnk
2014-09-03 06:00 - 2014-09-03 06:00 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2014-09-03 06:00 - 2014-09-03 06:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossfire Europe
2014-09-03 05:50 - 2014-09-03 05:50 - 00000000 ____D () C:\SG Interactive
2014-09-03 05:39 - 2014-09-03 05:39 - 00000181 _____ () C:\console.log
2014-09-03 05:39 - 2014-09-03 05:39 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\CrossFire EU
2014-09-03 05:38 - 2014-09-03 05:38 - 02156048 _____ (Reloaded Technologies) C:\Users\Jelínkovi\Downloads\Crossfire_downloader.exe
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Jelínkovi\AppData\Roaming\YJVIWV
2014-09-01 10:18 - 2014-09-01 10:18 - 00002086 _____ () C:\Users\Jelínkovi\AppData\Roaming\AIHGXB
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Jelínkovi\AppData\Roaming\QWMS
2014-09-01 10:18 - 2014-09-01 10:18 - 00001248 _____ () C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-28 10:49 - 2014-03-05 20:01 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-28 10:20 - 2014-03-05 19:15 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Mumble
2014-09-28 09:44 - 2009-07-14 06:45 - 00022656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-28 09:44 - 2009-07-14 06:45 - 00022656 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-28 09:43 - 2014-05-15 12:33 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz
2014-09-28 09:43 - 2009-07-14 17:18 - 00668542 _____ () C:\Windows\system32\perfh005.dat
2014-09-28 09:43 - 2009-07-14 17:18 - 00141202 _____ () C:\Windows\system32\perfc005.dat
2014-09-28 09:43 - 2009-07-14 07:13 - 01583226 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-28 09:40 - 2014-03-05 18:50 - 01654688 _____ () C:\Windows\WindowsUpdate.log
2014-09-28 09:37 - 2014-07-04 17:39 - 00010905 _____ () C:\Windows\setupact.log
2014-09-28 09:37 - 2014-07-04 17:39 - 00010094 _____ () C:\Windows\PFRO.log
2014-09-28 09:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-27 19:07 - 2014-05-15 12:34 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-27 18:49 - 2014-03-05 18:59 - 00001378 _____ () C:\Users\Jelínkovi\Desktop\Internet Explorer.lnk
2014-09-27 18:49 - 2002-03-24 08:27 - 00001174 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-27 18:49 - 2002-03-24 08:27 - 00001162 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-27 18:45 - 2014-03-05 19:32 - 00000000 ____D () C:\Program Files (x86)\Google
2014-09-25 16:50 - 2014-05-15 12:35 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Skype
2014-09-25 08:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-23 17:32 - 2014-07-05 10:42 - 00000000 ____D () C:\Program Files (x86)\Guild Wars 2
2014-09-23 17:01 - 2014-07-21 08:08 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-22 18:37 - 2014-08-23 13:16 - 00000750 _____ () C:\Users\Jelínkovi\Desktop\serial.txt
2014-09-22 18:37 - 2014-08-23 13:16 - 00000002 _____ () C:\Users\Jelínkovi\Desktop\myFile.txt
2014-09-22 18:00 - 2014-03-05 19:32 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-22 17:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-20 18:40 - 2014-07-05 10:38 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Guild Wars 2
2014-09-18 17:59 - 2014-06-11 14:38 - 00002533 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-09-18 17:59 - 2014-06-11 14:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-18 17:59 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Skype
2014-09-17 13:02 - 2014-07-21 08:54 - 00437436 _____ () C:\Windows\DirectX.log
2014-09-17 13:00 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-09-17 12:52 - 2014-03-05 20:29 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-09-17 12:42 - 2014-08-28 10:06 - 00000000 ____D () C:\Program Files (x86)\Game_Maker8
2014-09-17 12:42 - 2014-08-26 14:29 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\Stranger
2014-09-17 12:42 - 2014-06-22 16:00 - 00000000 ____D () C:\Program Files (x86)\Mount&Blade
2014-09-17 12:42 - 2014-04-09 07:27 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-09-17 12:42 - 2014-03-05 20:27 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-09-15 09:06 - 2014-03-05 19:58 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-11 18:24 - 2014-03-05 19:22 - 01557940 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 18:21 - 2014-04-30 23:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-10 18:49 - 2014-03-05 20:01 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-10 18:49 - 2014-03-05 20:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-10 18:49 - 2014-03-05 20:01 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-10 14:25 - 2014-03-07 15:55 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-09-10 14:15 - 2014-04-09 07:27 - 00000000 ____D () C:\Users\Jelínkovi\AppData\Roaming\DAEMON Tools Lite
2014-09-04 17:22 - 2014-04-09 12:59 - 00000000 ____D () C:\Users\Jelínkovi\Documents\gothic3
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-28 10:37
==================== End Of Log ============================
- Přílohy
-
- Addition.rar
- (4.71 KiB) Staženo 79 x
Re: Problem se spamem a internetem

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2014-04-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] () KU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Jelínkovi\AppData\Local\Akamai\netsession_win.exe" HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [Game Fire] => C:\Program Files (x86)\Smart PC Utilities\Game Fire\GFTray.exe [44032 2011-12-02] (Smart PC Utilities, Ltd.) HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] () HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Jelínkovi\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] () HKU\S-1-5-21-1875898016-1540026239-2231768052-1000\...\MountPoints2: {7c89468e-bf9e-11e3-bef1-001a9234e086} - E:\Autorun.exe BHO: Senses -> {11111111-1111-1111-1111-110611191115} -> C:\Program Files (x86)\Senses\Senses-bho64.dll No File BHO: No Name -> {11111111-1111-1111-1111-110611381131} -> No File BHO: Senses -> {11111111-1111-1111-1111-110611191115} -> C:\Program Files (x86)\Senses\Senses-bho64.dll No File BHO: No Name -> {11111111-1111-1111-1111-110611381131} -> No File CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 [X] S3 X6va027; \??\C:\Windows\SysWOW64\Drivers\X6va027 [X] 2014-09-28 11:35 - 2014-09-28 11:36 - 00010618 _____ () C:\Users\Jelínkovi\Desktop\FRST.txt 2014-09-28 11:33 - 2014-09-28 11:33 - 00112640 _____ (forum.viry.cz) C:\Users\Jelínkovi\Desktop\FRSTLauncher.exe 2014-09-28 09:35 - 2014-09-28 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-09-28 09:19 - 2014-09-28 09:38 - 00035767 _____ () C:\zoek-results.log 2014-09-28 09:18 - 2014-09-28 09:32 - 00000000 ____D () C:\zoek_backup 2014-09-28 09:16 - 2014-09-28 09:16 - 04256073 _____ () C:\Users\Jelínkovi\Downloads\zoek.rar 2014-09-28 09:15 - 2014-09-28 09:15 - 01290752 _____ () C:\Users\Jelínkovi\Desktop\zoek.exe 2014-09-27 19:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-09-27 18:59 - 2014-09-27 19:08 - 00000000 ____D () C:\AdwCleaner 2014-09-27 18:58 - 2014-09-27 18:58 - 00009791 _____ () C:\Users\Jelínkovi\Desktop\JRT.txt 2014-09-27 18:52 - 2014-09-27 18:52 - 00000000 ____D () C:\Windows\ERUNT 2014-09-27 18:51 - 2014-09-27 18:51 - 01699276 _____ (Thisisu) C:\Users\Jelínkovi\Desktop\JRT.exe 2014-09-27 18:51 - 2014-09-27 18:51 - 01373475 _____ () C:\Users\Jelínkovi\Desktop\adwcleaner_3.310.exe 2014-09-27 18:33 - 2014-09-27 18:33 - 01107968 _____ () C:\Users\Jelínkovi\Downloads\RSIT.exe 2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\rsit 2014-09-27 18:33 - 2014-09-27 18:33 - 00000000 ____D () C:\Program Files (x86)\trend micro 2014-09-25 17:02 - 2014-09-25 17:05 - 00578602 _____ () C:\spyhunter.fix 2014-09-25 16:52 - 2014-09-27 18:55 - 00000000 ____D () C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2014-09-25 16:52 - 2014-09-25 16:52 - 01508248 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\AIHGXB.exe 2014-09-25 16:52 - 2014-09-25 16:52 - 00001354 _____ () C:\Windows\Tasks\AIHGXB.job 2014-09-25 16:51 - 2014-09-25 16:51 - 01955736 _____ (Object Browser) C:\Users\Jelínkovi\AppData\Roaming\KEAYWJIF.exe 2014-09-25 16:51 - 2014-09-25 16:51 - 00001702 _____ () C:\Windows\Tasks\KEAYWJIF.job 2014-09-25 16:20 - 2014-09-25 16:20 - 00000000 ____D () C:\Users\Jelínkovi\Desktop\spyhunt 2014-09-25 13:05 - 2014-09-25 13:05 - 00000000 ____D () C:\Program Files (x86)\Enigma Software Group 2014-09-25 13:03 - 2014-09-25 16:53 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2014-09-25 07:12 - 2014-09-25 16:43 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-09-16 19:39 - 2014-09-16 19:39 - 01524120 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\YJVIWV.exe 2014-09-16 19:39 - 2014-09-16 19:39 - 00001354 _____ () C:\Windows\Tasks\YJVIWV.job 2014-09-16 19:38 - 2014-09-16 19:38 - 01972632 _____ (Info01HD-V2.1V16.09) C:\Users\Jelínkovi\AppData\Roaming\QWMS.exe 2014-09-16 19:38 - 2014-09-16 19:38 - 00001350 _____ () C:\Windows\Tasks\QWMS.job Task: {923059A7-C50B-4EFE-817D-E8A7C0DEB6CB} - \GPUP No Task File <==== ATTENTION Task: {932C784A-F216-4EB8-88ED-C4C4815C0004} - \Installer_shopperpro No Task File <==== ATTENTION Task: {A0850A9B-A27F-486D-A907-EB550801748A} - \YTAUpdate No Task File <==== ATTENTION AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 Hosts: EmptyTemp: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
