Zdravím, chtěl bych poprosit o kontrolu logu, Díky
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-02-2015
Ran by Blanka at 2015-02-25 08:46:29
Running from C:\Users\Blanka\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\uTorrent) (Version: 3.4.2.37754 - BitTorrent Inc.)
AdFender (HKLM-x32\...\AdFender) (Version: 1.82 - AdFender, Inc.)
AdmWin 2.47 (HKLM-x32\...\AdmWin_is1) (Version: - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.8.1.451 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.7.157 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
APB Reloaded (HKLM-x32\...\Steam App 113400) (Version: - Reloaded Productions)
ATI Catalyst Install Manager (HKLM\...\{95808236-DE32-EC77-0D88-11AF9C7CF80D}) (Version: 3.0.820.0 - ATI Technologies, Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bandicam (HKLM-x32\...\Bandicam) (Version: - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Call of Juarez (HKLM-x32\...\InstallShield_{07119BED-86AE-4AE3-97A5-45A118A3F06A}) (Version: 1.1.1.0 - Techland)
Call of Juarez (x32 Version: 1.1.1.0 - Techland) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.00 - Piriform)
Counter-Strike 1.6 v42 (HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Counter-Strike 1.6_is1) (Version: - Valve)
Cyti Web (HKLM\...\Cyti Web) (Version: 2015.02.01.132351 - Cyti Web) <==== ATTENTION
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.60 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.60 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.1.3 - Dell Inc.)
Dell Stage (HKLM-x32\...\{E2EBA7C0-8072-447F-856D-FFEE8D15B23B}) (Version: 1.5.201.0 - Fingertapps)
Dell Stage Remote (HKLM-x32\...\{AF4D3C63-009B-4A17-B02E-D395065DD3F0}) (Version: 2.0.0.43 - ArcSoft)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
Dell VideoStage (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
Dell VideoStage (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
EGR-ShellExtension (HKLM-x32\...\EGR-ShellExtension) (Version: 1.2.0.100 - EasternGraphics)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Freemake Video Converter verze 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
Gameforge Live 1.10.1 "Legend" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 1.10.1 - Gameforge)
Glary Utilities 5.13 (HKLM-x32\...\Glary Utilities 5) (Version: 5.13.0.26 - Glarysoft Ltd)
Google Drive (HKLM-x32\...\{65EACBB4-B0B8-4A5B-AE46-22DBE15C70B5}) (Version: 1.19.8406.6504 - Google, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.115 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6421.0 - IDT)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\...\{781A93CD-1608-427D-B7F0-D05C07795B25}) (Version: 2.1.41.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
Java 7 Update 76 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417076FF}) (Version: 7.0.760 - Oracle)
Java 7 Update 76 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217076FF}) (Version: 7.0.760 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.130 - PandoraTV)
LibreOffice 3.5 (HKLM-x32\...\{EF790F1C-CB0C-4B95-8C54-60783F3B6661}) (Version: 3.5.4.2 - The Document Foundation)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.319 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.319 - LogMeIn, Inc.) Hidden
Malwarebytes Anti-Malware verze 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Mc Titan FTB (HKLM-x32\...\Mc Titan FTB 1.0.0) (Version: 1.0.0 - Mc Titan)
Mc Titan FTB (x32 Version: 1.0.0 - Mc Titan) Hidden
MC Titan Minecraft Custom Tekkit (HKLM-x32\...\MC Titan Minecraft Custom Tekkit) (Version: - )
MC Titan Minecraft Feed the Beast (HKLM-x32\...\MC Titan Minecraft Feed the Beast) (Version: - )
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Minecraft1.7.2 (HKLM-x32\...\Minecraft1.7.2) (Version: - )
Mobogenie (HKLM-x32\...\Mobogenie) (Version: - Mobogenie.com) <==== ATTENTION
Mozilla Firefox 35.0.1 (x86 cs) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 cs)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
Norton Security Scan (HKLM-x32\...\NSS) (Version: 4.1.0.28 - Symantec Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{DEA314C4-0929-4250-BC92-98E4C105F28D}) (Version: 9.10.0129 - NVIDIA Corporation)
Opera Stable 27.0.1689.69 (HKLM-x32\...\Opera 27.0.1689.69) (Version: 27.0.1689.69 - Opera Software ASA)
osu! (HKLM-x32\...\{a8234307-9aae-461c-a762-009bfd6b049d}) (Version: latest - ppy Pty Ltd)
osu! (HKLM-x32\...\{aaa39a9e-ecdf-4e8a-8658-0ac7f217cbb5}) (Version: latest - ppy Pty Ltd)
osu! (HKLM-x32\...\{e6a7c0a6-4297-4590-924b-011b21f24208}) (Version: latest - ppy Pty Ltd)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.1 - Frank Heindörfer, Philip Chinery)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.88.617.2014 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\SeznamInstall) (Version: - Seznam.cz)
Seznam Software (HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\SeznamInstall) (Version: - Seznam.cz)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SlimDrivers (HKLM-x32\...\{A5457401-D56A-43F2-9524-78E54A7FC07A}) (Version: 2.2.32705 - SlimWare Utilities, Inc.)
Software Intel(R) PROSet/Wireless WiFi (HKLM\...\{295AEB79-B53A-4F1B-860F-7800BB7E3681}) (Version: 14.2.1000 - Intel Corporation)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
Team Fortress 2 + Steam version for Windows (HKLM-x32\...\{A5613512-E9DC-6468-9312-B2EC2D6B04F4}_is1) (Version: for Windows - )
TI USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{B1EB7FFF-6E44-43D8-869D-B78E44CD3E0F}) (Version: 1.12.14.0 - Texas Instruments Inc.)
TI USB3 Host Driver (x32 Version: 1.12.14.0 - Texas Instruments Inc.) Hidden
TmNationsForever (HKLM-x32\...\TmNationsForever_is1) (Version: - Nadeo)
Unity Web Player (HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Unity Web Player (HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\UnityWebPlayer) (Version: 4.6.2f1 - Unity Technologies ApS)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WeatherBug® (HKLM-x32\...\WeatherBug®) (Version: 10.0.7.4 - Earth Networks, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YTDownloader (HKLM-x32\...\YTDownloader) (Version: - YTDownloader)
Základní software zařízení HP Deskjet 2050 J510 series (HKLM\...\{F61FD928-A74D-4AF9-9667-BE2BB6F2C386}) (Version: 28.0.1313.0 - Hewlett-Packard Co.)
Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-412466861-1309505891-1087973670-1000_Classes\CLSID\{DEDBE4C9-9E87-40C5-B437-9AAB7EB9C667}\InprocServer32 -> C:\Program Files (x86)\EasternGraphics\EGR-ShellExtension\Win64\egr_se.dll (EasternGraphics)
==================== Restore Points =========================
22-12-2014 10:38:33 avast! antivirus system restore point
22-12-2014 14:18:56 Windows Update
26-12-2014 13:38:58 Windows Update
30-12-2014 02:02:01 Windows Update
02-01-2015 18:40:52 Windows Update
02-01-2015 19:10:50 SlimDrivers Installing Drivers
02-01-2015 19:29:33 SlimDrivers Installing Drivers
02-01-2015 19:32:51 Instalace balíčku ovladače zařízení: IDT Řadiče zvuku, videa a her
02-01-2015 19:34:28 Konfigurováno IDT Audio
02-01-2015 19:35:40 SlimDrivers Installing Drivers
02-01-2015 19:41:01 SlimDrivers Installing Drivers
02-01-2015 19:59:03 Removed SyncUP.
03-01-2015 21:24:27 SlimDrivers Installing Drivers
05-01-2015 13:25:19 SlimDrivers Installing Drivers
05-01-2015 14:09:37 Instalováno Realtek Ethernet Controller Driver
05-01-2015 14:10:34 Instalováno Realtek Ethernet Controller All-In-One Windows DriveU!^
05-01-2015 14:14:38 SlimDrivers Installing Drivers
06-01-2015 17:55:51 Windows Update
10-01-2015 18:47:09 Windows Update
14-01-2015 14:33:29 Windows Update
14-01-2015 15:22:10 Windows Update
18-01-2015 11:55:02 Windows Update
21-01-2015 19:07:12 Windows Update
24-01-2015 19:39:17 Windows Update
27-01-2015 09:10:28 SlimDrivers Installing Drivers
27-01-2015 09:15:21 SlimDrivers Installing Drivers
28-01-2015 13:35:01 Windows Update
28-01-2015 20:40:29 Windows Update
01-02-2015 00:00:11 Windows Update
01-02-2015 18:58:42 Odebráno: OpenOffice 4.1.1
05-02-2015 14:39:32 Windows Update
06-02-2015 14:12:57 Removed Quickset64.
08-02-2015 19:20:46 Windows Update
11-02-2015 17:47:53 Odebráno: AVG PC TuneUp 2015
11-02-2015 17:50:01 Odebráno: AVG PC TuneUp 2015 (cs-CZ)
16-02-2015 07:24:29 Windows Update
20-02-2015 07:58:30 Windows Update
23-02-2015 11:25:25 Windows Update
24-02-2015 13:32:49 paint.net 4.0.5
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {072728E9-68C6-469B-A8B9-CEBD04765BCA} - \SPDriver No Task File <==== ATTENTION
Task: {117FB88C-34A2-4C98-888B-4E0CCD9A5391} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-18] (AVAST Software)
Task: {22272F5B-34C8-4A72-9D5C-04D572DAA3DD} - System32\Tasks\AdobeAAMUpdater-1.0-Blanka-PC-Hoooonza => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {23EFD737-A653-4101-BCCB-E2BD15E7C291} - System32\Tasks\UERRV => C:\Users\Hoooonza\AppData\Roaming\UERRV.exe <==== ATTENTION
Task: {286BBF0A-012B-489D-9308-ABE926995D56} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2014-11-24] (Glarysoft Ltd)
Task: {28C99E85-13FC-4279-98C7-AF9278F26235} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2014-11-24] (Glarysoft Ltd)
Task: {36F594ED-001F-4B86-8AD3-BCEE8C74221D} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: {4B21E8FF-9CC3-4A79-B3F2-C0C2E5C10DBE} - System32\Tasks\SlimDrivers Startup => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [2013-09-24] (SlimWare Utilities, Inc.)
Task: {50824701-2E74-4B65-BCFB-CB91D4A6990A} - System32\Tasks\CIIAYI => C:\Users\Hoooonza\AppData\Roaming\CIIAYI.exe <==== ATTENTION
Task: {520AE2AE-C6F8-46C4-93F8-52B47195ABBD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-11-21] (Piriform Ltd)
Task: {5CD43345-BE5A-423B-8948-9A72466FD85A} - \BackgroundContainer Startup Task No Task File <==== ATTENTION
Task: {643E7174-8808-4554-98BF-E3937BC41476} - System32\Tasks\{EEA8F421-702C-4D7C-914F-33ED104F5652} => pcalua.exe -a C:\Users\Hoooonza\Desktop\mctitan_pokemine.exe -d C:\Users\Hoooonza\Desktop
Task: {766B9D00-6CAE-4D85-AC51-8D07B858DA39} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {7C5ACCF7-4BCE-43AC-A6E9-BB7D11FF21F4} - System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1003 => Chrome.exe
Task: {7DDEE8EB-5E3E-441C-AD3B-414EC6A4D2A2} - System32\Tasks\SMupdate1 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update1 <==== ATTENTION
Task: {83E22831-6D69-411B-B5CA-F6E2FD9B0D7E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-05] (Google Inc.)
Task: {95884C8D-1376-42F4-B7BE-7FD381CD1045} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated)
Task: {A1EE0AED-973B-40D4-89D3-A052ED9FD5A3} - System32\Tasks\{DEEF1A05-3A41-4521-B5B6-37C0F95287BC} => pcalua.exe -a C:\Users\Blanka\Desktop\mctitan172.exe -d C:\Users\Blanka\Desktop
Task: {A56AE36A-74EC-447E-BA20-40EA221A4A84} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-05] (Google Inc.)
Task: {B6D3AB4F-B40D-443E-A95F-D22A9768AA66} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-31] (PC-Doctor, Inc.)
Task: {B9D393B9-4E35-4420-A978-CF7CEA844774} - System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1000 => Firefox.exe
Task: {BAB7DB11-9103-4F60-B032-21DBCE8D407B} - System32\Tasks\{048314BC-FED5-4D79-8976-AE33D3EDBB9E} => C:\Users\Hoooonza\Desktop\Minecraft-warez-Launcher-1.7.10.exe
Task: {BFF47242-C4CB-48CF-AD40-CED5B86A4205} - System32\Tasks\YTDownloaderUpd => C:\Program Files (x86)\YTDownloader\updater.exe <==== ATTENTION
Task: {E5EFAFA6-08E9-4EEA-88CB-06A8B6C83493} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {E82CE97F-3C7E-4D4F-8DEB-2BAA23282E4E} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {EBE7BFDA-1DFD-490E-B4F9-9D0E78A8673B} - System32\Tasks\Norton Security Scan for NightCore => C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation)
Task: {F1F9D33D-0F33-42F4-978C-4C7848B2908C} - System32\Tasks\Opera scheduled Autoupdate 1420437773 => C:\Program Files (x86)\Opera\launcher.exe [2015-02-10] (Opera Software)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\CIIAYI.job => C:\Users\Hoooonza\AppData\Roaming\CIIAYI.exe <==== ATTENTION
Task: C:\windows\Tasks\GlaryInitialize 5.job => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\Norton Security Scan for NightCore.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
Task: C:\windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
Task: C:\windows\Tasks\UERRV.job => C:\Users\Hoooonza\AppData\Roaming\UERRV.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) ==============

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o kontrolu
Zdravim
Poprosim o log FRST.txt
-
zdenek72
- 3. Stupeň Varování
- Příspěvky: 106
- Registrován: 09 úno 2010 15:18
- Bydliště: Plzen, Czech Republic
- Kontaktovat uživatele:
Re: Prosím o kontrolu
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-02-2015
Ran by Blanka (administrator) on BLANKA-PC on 25-02-2015 10:22:11
Running from C:\Users\Blanka\Desktop
Loaded Profiles: Blanka & Hoooonza (Available profiles: Blanka & Hoooonza & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
() C:\Program Files (x86)\Opera\27.0.1689.69\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-02-17] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [reg_svr] => "C:\windows\SysWoW64\regsvr32.exe" /s "C:\Users\Blanka\AppData\Roaming\glister\nvm.dll"
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-11-24] (Glarysoft Ltd)
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [uTorrent] => C:\Users\Blanka\AppData\Roaming\uTorrent\uTorrent.exe [1374032 2015-02-16] (BitTorrent Inc.)
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\MountPoints2: {aee647c9-43be-11e1-aeee-806e6f6e6963} - D:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AdFender.lnk
ShortcutTarget: AdFender.lnk -> C:\Program Files (x86)\AdFender\AdFender.exe (AdFender, Inc.)
Startup: C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk -> C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk *
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpp ... XX6WS11HLD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... XX6WS11HLD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/UP97_FRPage
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {E1BFFB17-C02F-4424-9D75-91514E720970} URL = http://search.conduit.com/ResultsExt.as ... 96519&UM=1
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{D9878FF6-B546-495F-B936-597080B07E0C}: [NameServer] 0.0.0.0
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
FF DefaultSearchEngine: Seznam
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Blanka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1003: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Hoooonza\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Hoooonza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\omiga-plus.xml
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\seznam-avast.xml
FF Extension: Seznam lištička - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-05]
FF Extension: Adblock Plus - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-19]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-26]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-18]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\extensions\fftoolbar2014@etech.com
FF HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultSearchKeyword: Profile 1 -> seznam.cz
CHR DefaultSearchURL: Profile 1 -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Profile 1 -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-13]
CHR Extension: (Google Docs) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-13]
CHR Extension: (Google Drive) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-13]
CHR Extension: (YouTube) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-13]
CHR Extension: (Google Search) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-13]
CHR Extension: (Avast SafePrice) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2014-12-18]
CHR Extension: (Google Sheets) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-13]
CHR Extension: (Avast Online Security) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-19]
CHR Extension: (Skype Click to Call) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-02-02]
CHR Extension: (Google Wallet) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-13]
CHR Extension: (Gmail) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-13]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Blanka\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-11-21]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [eibfgbclmgnmffinenpipoibfdoblond] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-rv-1.5.4.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkfpcckoflkdgjdobdkpclgngaahgbpi] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-email-1.3.1.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ghoooididkjbjjldgojdgceoinbhbjmh] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-slovnik-1.2.2.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lelcohngbjgpiibagnfmncojacafbbpg] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\Partner-1.1.0.crx [2014-07-19]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-18]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-18]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-18] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-18] (Avast Software)
S3 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [921664 2011-05-19] (Intel Corporation) [File not signed]
S3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1335360 2011-05-19] (Intel Corporation) [File not signed]
S3 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [995392 2011-05-19] (Intel Corporation) [File not signed]
S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-02-16] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-16] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76152 2014-11-04] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [X]
S2 Update Cyti Web; "C:\Program Files (x86)\Cyti Web\updateCytiWeb.exe" [X]
S2 Util Cyti Web; "C:\Program Files (x86)\Cyti Web\bin\utilCytiWeb.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-18] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2015-02-05] (Symantec Corporation)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [20160 2014-11-25] (Glarysoft Ltd)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-25] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2015-01-27] ()
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-18] (Avast Software)
R1 {3560b757-0519-45b3-a215-cfb94afd0821}Gw64; C:\Windows\System32\drivers\{3560b757-0519-45b3-a215-cfb94afd0821}Gw64.sys [48832 2015-02-05] (StdLib)
R1 {4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64; C:\Windows\System32\drivers\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64.sys [48832 2015-02-10] (StdLib)
R1 {c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64; C:\Windows\System32\drivers\{c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64.sys [48832 2015-02-06] (StdLib)
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S2 SPDRIVER_1489.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1489.0.0.0\jsdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 10:22 - 2015-02-25 10:23 - 00028949 _____ () C:\Users\Blanka\Desktop\FRST.txt
2015-02-25 10:21 - 2015-02-25 10:21 - 02087424 _____ (Farbar) C:\Users\Blanka\Desktop\FRST64.exe
2015-02-25 08:40 - 2015-02-25 10:22 - 00000000 ____D () C:\FRST
2015-02-24 19:36 - 2015-02-24 19:36 - 00000000 ____D () C:\Users\Hoooonza\Desktop\NakashiCraft
2015-02-24 19:35 - 2015-02-24 19:35 - 00000000 ____D () C:\Users\Hoooonza\Desktop\Nakashi_pack
2015-02-24 18:04 - 2015-02-24 18:05 - 06855059 _____ () C:\Users\Hoooonza\Downloads\Nakashi_pack1.1.3.rar
2015-02-24 17:49 - 2015-02-24 17:49 - 00000000 ____D () C:\Users\Hoooonza\Documents\Uživatelské soubory aplikace paint.net
2015-02-24 14:36 - 2015-02-24 14:36 - 00038842 _____ () C:\Users\Hoooonza\Desktop\pack.pdn
2015-02-24 14:30 - 2015-02-24 14:30 - 00001202 _____ () C:\Users\Hoooonza\Desktop\paint.net.lnk
2015-02-24 14:17 - 2015-02-24 17:57 - 00000000 ____D () C:\Users\Hoooonza\Desktop\Nový YT pack
2015-02-24 14:17 - 2015-02-24 14:42 - 00000000 ____D () C:\Users\Hoooonza\Desktop\MangaLive
2015-02-24 14:02 - 2015-02-24 14:03 - 04170521 _____ () C:\Users\Hoooonza\Desktop\MyLol.zip
2015-02-24 13:51 - 2015-02-24 13:52 - 00000000 ____D () C:\Users\Hoooonza\Desktop\TextPack
2015-02-24 13:38 - 2015-02-24 13:38 - 00674720 _____ ( ) C:\Users\Hoooonza\Downloads\minecraft-1-5-2-plna-hra
2015-02-24 13:38 - 2015-02-24 13:38 - 00674720 _____ ( ) C:\Users\Hoooonza\Desktop\minecraft-1-5-2-plna-hra
2015-02-24 13:35 - 2015-02-24 13:35 - 00001214 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2015-02-24 13:35 - 2015-02-24 13:35 - 00001202 _____ () C:\Users\Public\Desktop\paint.net.lnk
2015-02-24 13:33 - 2015-02-24 13:35 - 00000000 ____D () C:\Program Files\paint.net
2015-02-24 13:32 - 2015-02-24 13:41 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\paint.net
2015-02-24 13:31 - 2015-02-24 13:31 - 06528454 _____ () C:\Users\Hoooonza\Desktop\paint.net.4.0.5.install.zip
2015-02-24 13:29 - 2015-02-24 13:31 - 06528454 _____ () C:\Users\Hoooonza\Downloads\paint.net.4.0.5.install.zip
2015-02-24 12:39 - 2015-02-20 12:19 - 00000000 ____D () C:\Users\Hoooonza\Desktop\1.5.2BC-extra
2015-02-24 12:36 - 2015-02-24 12:37 - 04760644 _____ () C:\Users\Hoooonza\Downloads\minecrivel (1).zip
2015-02-24 12:35 - 2015-02-24 12:40 - 46738630 _____ () C:\Users\Hoooonza\Desktop\minecraft (2).rar
2015-02-24 12:29 - 2015-02-24 12:30 - 53186993 _____ () C:\Users\Hoooonza\Downloads\minecraft (2).rar
2015-02-24 12:24 - 2015-02-24 12:24 - 04760644 _____ () C:\Users\Hoooonza\Downloads\minecrivel.zip
2015-02-24 11:45 - 2015-02-24 11:57 - 200063578 _____ () C:\Users\Hoooonza\Downloads\Sony-Vegas-Pro-10.0.rar
2015-02-24 11:44 - 2015-02-24 11:44 - 01826135 _____ () C:\Users\Hoooonza\Downloads\Crack-Sony-Vegas-Pro-10.0.rar
2015-02-24 09:46 - 2015-02-24 12:06 - 00000000 ____D () C:\Users\Hoooonza\Desktop\You
2015-02-24 09:40 - 2015-02-24 09:40 - 00000574 _____ () C:\Users\Hoooonza\Desktop\Fraps.lnk
2015-02-24 09:40 - 2015-02-24 09:40 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
2015-02-24 09:38 - 2015-02-24 09:38 - 00000197 _____ () C:\windows\system32\2015-02-24-08-38-50.076-AvastVBoxSVC.exe-3796.log
2015-02-24 07:48 - 2015-02-24 07:48 - 00022588 _____ () C:\Users\Hoooonza\Desktop\hs_err_pid5536.log
2015-02-24 07:08 - 2015-02-24 07:08 - 00000197 _____ () C:\windows\system32\2015-02-24-06-08-04.057-AvastVBoxSVC.exe-4412.log
2015-02-23 11:15 - 2015-02-23 11:16 - 00000197 _____ () C:\windows\system32\2015-02-23-10-15-55.073-AvastVBoxSVC.exe-3344.log
2015-02-22 16:06 - 2015-02-22 16:06 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-02-22 16:05 - 2015-02-22 16:06 - 05007216 _____ (Adobe Systems Inc.) C:\Users\Blanka\Downloads\Shockwave_Installer_Slim.exe
2015-02-22 16:02 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer (2).exe
2015-02-22 16:02 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer (1).exe
2015-02-22 16:02 - 2015-02-22 16:02 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Unity
2015-02-22 16:01 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer.exe
2015-02-22 15:53 - 2015-02-22 15:53 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\.minecraft
2015-02-22 15:53 - 2015-02-22 15:52 - 53186993 _____ () C:\Users\Blanka\Desktop\minecraft.rar
2015-02-22 15:52 - 2015-02-22 15:52 - 53186993 _____ () C:\Users\Blanka\Downloads\minecraft.rar
2015-02-22 15:38 - 2015-02-22 15:38 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Steam
2015-02-21 12:07 - 2015-02-21 12:07 - 00000197 _____ () C:\windows\system32\2015-02-21-11-07-02.030-AvastVBoxSVC.exe-4588.log
2015-02-21 09:12 - 2015-02-21 09:12 - 00002144 _____ () C:\Users\Hoooonza\Desktop\Minecraft.lnk
2015-02-21 09:12 - 2015-02-21 09:12 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-02-21 09:11 - 2015-02-21 09:12 - 11995143 _____ () C:\Users\Hoooonza\Downloads\CraftBukkit-1.5.2.rar
2015-02-21 08:58 - 2015-02-21 09:10 - 115388610 _____ () C:\Users\Hoooonza\Downloads\Minecraft-1.7.2.-na-100%-funguje-.rar
2015-02-21 08:55 - 2015-02-21 08:56 - 11012464 _____ () C:\Users\Hoooonza\Downloads\Minecraft-1.7.2.rar
2015-02-21 08:45 - 2015-02-24 19:37 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\.minecraft
2015-02-21 08:00 - 2015-02-21 08:00 - 00002257 _____ () C:\Users\Hoooonza\Documents\Můj film.wlmp
2015-02-21 07:46 - 2015-02-21 07:47 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{16F58C8B-951F-4E17-B3B9-700B1C2558F6}
2015-02-21 07:12 - 2015-02-21 07:13 - 51714155 _____ () C:\Users\Hoooonza\Downloads\minecraft.rar
2015-02-21 06:59 - 2015-02-24 11:11 - 00000000 ____D () C:\Users\Hoooonza\Desktop\New
2015-02-21 06:59 - 2015-02-21 06:59 - 51714155 _____ () C:\Users\Hoooonza\Downloads\minecraft (1).rar
2015-02-21 06:57 - 2015-02-21 06:57 - 00000197 _____ () C:\windows\system32\2015-02-21-05-57-02.065-AvastVBoxSVC.exe-3932.log
2015-02-20 14:21 - 2015-02-20 14:27 - 05564661 _____ () C:\Users\Hoooonza\Downloads\minecraft.jar
2015-02-20 13:49 - 2015-02-20 13:49 - 00000197 _____ () C:\windows\system32\2015-02-20-12-49-27.021-AvastVBoxSVC.exe-4212.log
2015-02-20 07:48 - 2015-02-20 07:49 - 00000197 _____ () C:\windows\system32\2015-02-20-06-48-56.040-AvastVBoxSVC.exe-3088.log
2015-02-19 17:46 - 2015-02-24 17:51 - 00000693 _____ () C:\Users\Hoooonza\Desktop\Čarovný-Minecraft-1.5.2.lnk
2015-02-19 17:16 - 2015-02-19 17:16 - 00000946 _____ () C:\Users\Hoooonza\Desktop\LogMeIn Hamachi.lnk
2015-02-19 17:10 - 2015-02-19 17:22 - 108060963 _____ () C:\Users\Hoooonza\Downloads\Čarovný-Minecraft-1.5.2.rar
2015-02-19 07:21 - 2015-02-19 07:21 - 00000197 _____ () C:\windows\system32\2015-02-19-06-21-05.044-AvastVBoxSVC.exe-3680.log
2015-02-19 07:19 - 2015-02-19 07:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-02-19 07:19 - 2015-02-19 07:19 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-02-18 17:55 - 2015-02-18 17:55 - 00002778 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2015-02-18 07:27 - 2015-02-18 07:27 - 00000197 _____ () C:\windows\system32\2015-02-18-06-27-44.039-AvastVBoxSVC.exe-4256.log
2015-02-17 16:33 - 2015-02-17 16:34 - 05054184 _____ () C:\Users\Blanka\Desktop\Nodus-1.5.2.rar
2015-02-17 07:44 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-02-17 07:44 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-02-17 07:44 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-02-17 07:44 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-02-16 18:55 - 2015-02-22 15:54 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-02-16 18:54 - 2015-02-16 18:54 - 00016948 _____ () C:\Users\Blanka\Downloads\[CzT]Minecraft_1_7_2_2013_CZ_.torrent
2015-02-16 08:04 - 2015-02-16 08:04 - 00000197 _____ () C:\windows\system32\2015-02-16-07-04-28.005-AvastVBoxSVC.exe-3660.log
2015-02-16 08:01 - 2015-02-25 08:32 - 00001350 _____ () C:\windows\setupact.log
2015-02-16 08:01 - 2015-02-16 08:01 - 00000000 _____ () C:\windows\setuperr.log
2015-02-16 07:59 - 2015-02-16 07:59 - 00000766 _____ () C:\windows\PFRO.log
2015-02-12 13:11 - 2015-02-25 08:27 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-02-12 13:11 - 2015-02-12 13:11 - 00002021 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-02-12 11:34 - 2015-02-12 11:34 - 02347384 _____ (ESET) C:\Users\Blanka\Desktop\esetsmartinstaller_csy (1).exe
2015-02-12 11:23 - 2015-02-12 11:23 - 00003824 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1420437773
2015-02-12 10:43 - 2015-02-12 10:43 - 00000197 _____ () C:\windows\system32\2015-02-12-09-43-54.047-AvastVBoxSVC.exe-4776.log
2015-02-12 10:25 - 2015-02-25 08:50 - 00000000 ____D () C:\Program Files\trend micro
2015-02-11 18:03 - 2015-02-11 18:03 - 00000197 _____ () C:\windows\system32\2015-02-11-17-03-47.032-AvastVBoxSVC.exe-3664.log
2015-02-11 10:10 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-02-11 10:10 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-02-11 10:10 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-02-11 10:09 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-02-11 10:09 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-02-11 10:09 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-02-11 10:09 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-02-11 10:09 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-02-11 10:09 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-02-11 10:09 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-02-11 10:09 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-02-11 10:09 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-02-11 10:09 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-02-11 10:09 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-02-11 10:09 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-02-11 10:09 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-02-11 10:09 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-02-11 10:09 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-02-11 10:09 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-02-11 10:09 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-02-11 10:09 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 10:09 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-02-11 10:09 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-02-11 10:09 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-02-11 10:09 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-02-11 10:09 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-02-11 10:09 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-02-11 10:09 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-02-11 10:09 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-02-11 10:09 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-02-11 10:09 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-02-11 10:09 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-02-11 10:09 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-02-11 10:09 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-02-11 10:09 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-02-11 10:09 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-02-11 10:09 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 10:09 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-02-11 10:09 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-02-11 10:09 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-02-11 10:09 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-02-11 10:09 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-02-11 10:09 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-02-11 10:09 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-02-11 10:09 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-02-11 10:09 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-02-11 10:09 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-02-11 10:09 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-02-11 10:09 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-02-11 10:09 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-02-11 10:08 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-02-11 10:08 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-02-11 10:08 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-02-11 10:08 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-02-11 10:08 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-02-11 10:08 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-02-11 10:08 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-02-11 10:08 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-02-11 10:08 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-02-11 10:08 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-02-11 10:08 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-02-11 10:08 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-02-11 10:08 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-02-11 10:08 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-02-11 10:08 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-02-11 10:08 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-02-11 10:08 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-02-11 10:08 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-02-11 10:08 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-02-11 10:08 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-02-11 10:08 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-02-11 10:08 - 2014-10-04 03:10 - 03722752 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-02-11 10:08 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-02-11 10:08 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2015-02-11 10:08 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-02-11 10:08 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-02-11 10:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-02-11 10:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-02-11 10:07 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-02-11 10:07 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-02-11 10:07 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-02-11 10:07 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-02-11 10:07 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-02-11 10:07 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-02-11 10:07 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-02-11 10:07 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-02-11 10:07 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2015-02-11 10:06 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-02-11 09:55 - 2015-02-11 09:55 - 00000197 _____ () C:\windows\system32\2015-02-11-08-55-44.028-AvastVBoxSVC.exe-3984.log
2015-02-10 18:20 - 2015-02-10 01:29 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64.sys
2015-02-10 10:55 - 2015-02-10 10:55 - 00183090 _____ () C:\Users\Blanka\Downloads\00322924-01-2015-EVP.zip
2015-02-10 10:20 - 2015-02-10 10:20 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\AVG
2015-02-10 10:18 - 2015-02-10 10:18 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Avg
2015-02-09 14:28 - 2015-02-09 14:28 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\AVG
2015-02-09 14:27 - 2015-02-09 14:27 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Avg
2015-02-09 14:27 - 2015-02-09 14:27 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-02-09 14:25 - 2015-02-21 07:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-02-09 14:25 - 2015-02-09 14:29 - 00000000 ____D () C:\ProgramData\AVG
2015-02-09 14:25 - 2015-02-09 14:27 - 00000000 ____D () C:\Users\Hoooonza\Documents\Freemake
2015-02-09 14:25 - 2015-02-09 14:26 - 00000000 ____D () C:\ProgramData\Freemake
2015-02-09 14:25 - 2015-02-09 14:25 - 00001340 _____ () C:\Users\Hoooonza\Desktop\Freemake Video Converter.lnk
2015-02-09 14:25 - 2015-02-09 14:25 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-02-09 14:23 - 2015-02-09 14:25 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-02-09 14:23 - 2015-02-09 14:23 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\RHEng
2015-02-09 14:20 - 2015-02-09 14:20 - 08042929 _____ () C:\Users\Hoooonza\Downloads\FreemakeVideoConverter-setup.exe
2015-02-08 20:10 - 2015-02-08 20:10 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{DC4AFAF8-92FD-42E6-BB9D-947156889420}
2015-02-08 19:52 - 2015-02-08 19:54 - 20074891 _____ () C:\Users\Hoooonza\Downloads\52361 Skillet - Hero.osz
2015-02-08 19:51 - 2015-02-08 19:51 - 07322524 _____ () C:\Users\Hoooonza\Downloads\13835 Iyaz - Replay.osz
2015-02-08 19:12 - 2015-02-16 08:01 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-08 19:12 - 2015-02-16 08:01 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-08 19:12 - 2015-02-12 11:18 - 00003960 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-08 19:12 - 2015-02-12 11:18 - 00003708 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-08 19:10 - 2015-02-08 19:10 - 00000197 _____ () C:\windows\system32\2015-02-08-18-10-10.054-AvastVBoxSVC.exe-3972.log
2015-02-07 15:25 - 2015-02-12 11:19 - 00000000 ____D () C:\Users\Blanka\AppData\Local\CrashDumps
2015-02-07 15:24 - 2015-02-07 15:24 - 00000197 _____ () C:\windows\system32\2015-02-07-14-24-12.098-AvastVBoxSVC.exe-4072.log
2015-02-07 15:24 - 2015-02-06 19:34 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64.sys
2015-02-06 15:41 - 2015-02-06 15:41 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\AdFender
2015-02-06 14:09 - 2015-02-06 14:09 - 00000000 ____D () C:\Users\NightCore\AppData\Local\LogMeIn
2015-02-06 14:09 - 2015-02-06 14:09 - 00000000 ____D () C:\Users\NightCore\AppData\Local\AdFender
2015-02-06 12:01 - 2015-02-06 12:01 - 00000000 ____D () C:\ProgramData\GlarySoft
2015-02-06 11:04 - 2015-02-06 11:04 - 00001366 _____ () C:\Users\Blanka\Desktop\CCleaner – zástupce.lnk
2015-02-06 10:25 - 2015-02-06 10:26 - 00000000 ____D () C:\Users\Blanka\AppData\Local\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\ProgramData\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\Program Files (x86)\AdFender
2015-02-06 10:12 - 2015-02-05 17:29 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{3560b757-0519-45b3-a215-cfb94afd0821}Gw64.sys
2015-02-06 09:14 - 2015-02-25 09:02 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-06 09:14 - 2015-02-12 11:05 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-02-06 09:14 - 2015-02-06 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-06 09:14 - 2015-02-06 09:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-06 09:14 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-02-06 09:14 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-02-05 15:52 - 2015-02-19 08:56 - 00000460 ____H () C:\windows\Tasks\Norton Security Scan for NightCore.job
2015-02-05 15:52 - 2015-02-05 15:52 - 00003628 _____ () C:\windows\System32\Tasks\Norton Security Scan for NightCore
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\windows\system32\Drivers\NSSx64
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\ProgramData\Norton
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\Program Files (x86)\Norton Security Scan
2015-02-05 15:51 - 2015-02-05 15:51 - 00001921 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\WeatherBug®.lnk
2015-02-05 15:51 - 2015-02-05 15:51 - 00001897 _____ () C:\Users\NightCore\Desktop\WeatherBug®.lnk
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\Users\NightCore\AppData\Local\IsolatedStorage
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\Program Files\Earth Networks
2015-02-05 15:50 - 2015-02-05 15:51 - 00000000 __HDC () C:\ProgramData\{FA77A43D-F6ED-4924-87B5-517C061388C6}
2015-02-05 15:49 - 2015-02-05 15:49 - 00675988 _____ () C:\Users\NightCore\Desktop\minecraft.exe.EXE
2015-02-05 15:49 - 2015-02-05 15:49 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online
2015-02-05 15:49 - 2015-02-05 15:49 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\ImperiaOnline
2015-02-05 14:26 - 2015-02-05 14:26 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\.minecraft
2015-02-04 21:04 - 2015-02-04 21:05 - 03386604 _____ () C:\Users\NightCore\Downloads\42481 Eiffel 65 - I'm Blue (Da Ba Dee).osz
2015-02-04 20:59 - 2015-02-04 20:59 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\vlc
2015-02-04 20:58 - 2015-02-04 21:01 - 00000000 ____D () C:\Users\NightCore\Documents\Kawaii
2015-02-03 20:16 - 2015-02-03 20:19 - 00002443 _____ () C:\Users\NightCore\Desktop\Anime.lnk
2015-02-03 20:13 - 2015-02-03 20:13 - 00014110 ____H () C:\Users\NightCore\Desktop\photoshop – zástupce.lnk
2015-02-03 18:04 - 2015-02-03 18:04 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001 (2)
2015-02-03 18:03 - 2015-02-03 18:03 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001 (1)
2015-02-03 18:03 - 2015-02-03 18:03 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001
2015-02-03 17:17 - 2015-02-03 17:17 - 07322524 _____ () C:\Users\NightCore\Downloads\13835 Iyaz - Replay.osz
2015-02-03 17:05 - 2015-02-03 17:05 - 00000955 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2015-02-03 17:03 - 2015-02-06 14:28 - 00000000 ____D () C:\Users\NightCore\AppData\Local\osu!
2015-02-03 15:58 - 2015-02-03 15:58 - 00069816 _____ () C:\Users\NightCore\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-03 14:06 - 2015-02-03 21:41 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Skype
2015-02-03 14:06 - 2015-02-03 14:06 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Skype
2015-02-03 14:03 - 2015-02-06 16:02 - 00000000 ____D () C:\Users\NightCore\AppData\Local\LogMeIn Hamachi
2015-02-03 14:03 - 2015-02-03 14:03 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\IDT
2015-02-02 22:32 - 2015-02-02 22:32 - 00000000 ____D () C:\Users\NightCore\Documents\Tiskárna
2015-02-02 21:42 - 2015-02-02 21:42 - 00000000 ____D () C:\Users\NightCore\AppData\Local\HP
2015-02-02 21:38 - 2015-02-02 21:38 - 00000000 ____D () C:\Users\NightCore\AppData\Local\PunkBuster
2015-02-02 21:27 - 2015-02-02 22:33 - 00000000 ____D () C:\Users\NightCore\Documents\Battlefield Play4Free
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Mozilla
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Mozilla
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Macromedia
2015-02-02 21:00 - 2015-02-02 21:00 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Windows Live
2015-02-02 21:00 - 2015-02-02 21:00 - 00000000 ____D () C:\Users\NightCore\AppData\Local\{BF7B76A3-486A-4C14-B69B-4809DF2B454E}
2015-02-02 20:58 - 2015-02-02 20:58 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\WinRAR
2015-02-02 20:40 - 2015-02-02 20:40 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\AVAST Software
2015-02-02 20:39 - 2015-02-02 21:17 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-02 20:39 - 2015-02-02 20:44 - 00002310 _____ () C:\Users\NightCore\Desktop\Google Chrome.lnk
2015-02-02 20:39 - 2015-02-02 20:39 - 00001395 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-02 20:39 - 2015-02-02 20:39 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Adobe
2015-02-02 20:38 - 2015-02-02 20:38 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Intel
2015-02-02 20:38 - 2015-02-02 20:38 - 00000000 ____D () C:\Users\NightCore\AppData\Local\VirtualStore
2015-02-02 20:37 - 2015-02-03 14:03 - 00000000 ____D () C:\Users\NightCore\AppData\Local\SoftThinks
2015-02-02 20:37 - 2015-02-02 23:21 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Google
2015-02-02 20:37 - 2015-02-02 20:39 - 00000000 ____D () C:\Users\NightCore
2015-02-02 20:37 - 2015-02-02 20:37 - 00000020 ___SH () C:\Users\NightCore\ntuser.ini
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Šablony
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Soubory cookie
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Poslední
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Okolní tiskárny
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Okolní síť
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Nabídka Start
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Dokumenty
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Obrázky
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Hudba
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Filmy
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Data aplikací
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\AppData\Local\Data aplikací
2015-02-02 20:37 - 2012-01-21 00:44 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Macromedia
2015-02-02 20:37 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-02 20:37 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-02-02 20:33 - 2015-02-02 21:34 - 06000640 _____ () C:\Program Files (x86)\GUT523E.tmp
2015-02-02 20:33 - 2015-02-02 20:33 - 00000000 ____D () C:\Program Files (x86)\GUM522D.tmp
2015-02-02 20:32 - 2015-02-02 20:32 - 00880784 _____ (Google Inc.) C:\Users\Blanka\Downloads\ChromeSetup.exe
2015-02-01 18:48 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\Cyti Web
2015-02-01 18:48 - 2015-02-01 18:48 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-02-01 18:47 - 2015-02-25 07:42 - 00001348 _____ () C:\windows\Tasks\UERRV.job
2015-02-01 18:47 - 2015-02-12 13:43 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-02-01 18:47 - 2015-02-01 18:47 - 00004382 _____ () C:\windows\System32\Tasks\UERRV
2015-02-01 18:46 - 2015-02-25 07:58 - 00001350 _____ () C:\windows\Tasks\CIIAYI.job
2015-02-01 18:46 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\b293b0ed-4515-48e8-8fd9-956160943535
2015-02-01 18:46 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\1acf32df-b1fe-4175-996d-52aaa728b99a
2015-02-01 18:46 - 2015-02-01 18:46 - 00004384 _____ () C:\windows\System32\Tasks\CIIAYI
2015-02-01 18:46 - 2015-02-01 18:46 - 00003730 _____ () C:\windows\System32\Tasks\SMupdate1
2015-02-01 18:46 - 2015-02-01 18:46 - 00003590 _____ () C:\windows\System32\Tasks\YTDownloader
2015-02-01 18:46 - 2015-02-01 18:46 - 00003580 _____ () C:\windows\System32\Tasks\YTDownloaderUpd
2015-02-01 18:46 - 2015-02-01 18:46 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
2015-02-01 18:46 - 2015-02-01 18:46 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\globalUpdate
2015-02-01 18:45 - 2015-02-12 13:43 - 00000000 ____D () C:\Program Files (x86)\YTDownloader
2015-02-01 18:45 - 2015-02-02 13:59 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2015-02-01 18:45 - 2015-02-01 18:45 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\CrashRpt
2015-01-31 15:22 - 2015-01-31 19:40 - 00000000 ____D () C:\Users\Hoooonza\Documents\Battlefield Play4Free
2015-01-30 19:02 - 2015-01-30 19:02 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Unity
2015-01-30 18:36 - 2015-01-30 18:36 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Unity
2015-01-30 18:04 - 2015-01-30 18:04 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\by_dekart811
2015-01-30 16:04 - 2015-01-30 16:04 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\AVAST Software
2015-01-30 14:58 - 2015-01-30 14:58 - 00002996 _____ () C:\windows\System32\Tasks\{048314BC-FED5-4D79-8976-AE33D3EDBB9E}
2015-01-30 14:54 - 2015-01-30 14:55 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{D65FEFB8-0AD0-482D-9F0E-EEAE617043C6}
2015-01-29 22:40 - 2015-01-29 22:40 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{4357E4C1-4F2B-4B7E-BB2D-70688718B650}
2015-01-29 20:44 - 2015-02-09 14:17 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\CrashDumps
2015-01-29 14:03 - 2014-08-25 16:05 - 01592398 _____ (TeamExtreme) C:\Users\Guest\Desktop\Minecraft.exe
2015-01-28 21:02 - 2015-01-28 21:02 - 00003152 _____ () C:\windows\System32\Tasks\{EEA8F421-702C-4D7C-914F-33ED104F5652}
2015-01-28 21:01 - 2015-02-22 19:43 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\mctpokemine
2015-01-28 20:50 - 2015-01-28 20:50 - 00001366 _____ () C:\Users\Hoooonza\Desktop\CCleaner – zástupce.lnk
2015-01-28 20:33 - 2015-01-28 20:32 - 00320424 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00189352 _____ (Oracle Corporation) C:\Users\Hoooonza\Desktop\java.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-28 20:30 - 2015-01-28 20:29 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-28 07:53 - 2015-02-06 14:05 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 07:53 - 2015-02-06 11:06 - 00003854 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-27 17:01 - 2015-01-27 17:02 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{F5299567-2588-4D4A-AE5B-08082A2551FC}
2015-01-27 07:43 - 2015-01-27 07:43 - 00000197 _____ () C:\windows\system32\2015-01-27-06-43-06.099-AvastVBoxSVC.exe-4136.log
2015-01-27 07:43 - 2015-01-27 07:43 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-01-27 07:43 - 2015-01-27 07:43 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf
2015-01-26 21:04 - 2015-01-26 21:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 20:59 - 2015-01-26 21:05 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000057 _____ () C:\ProgramData\Ament.ini
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\ProgramData\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\Program Files\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\Program Files (x86)\HP
2015-01-26 20:48 - 2015-01-26 20:48 - 00000197 _____ () C:\windows\system32\2015-01-26-19-48-03.086-AvastVBoxSVC.exe-3876.log
2015-01-26 08:10 - 2015-01-26 08:10 - 00000197 _____ () C:\windows\system32\2015-01-26-07-10-21.043-AvastVBoxSVC.exe-4876.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 10:07 - 2012-01-21 00:26 - 01847600 _____ () C:\windows\WindowsUpdate.log
2015-02-25 09:17 - 2014-11-19 09:17 - 00000000 ____D () C:\Users\Blanka\Desktop\čističe
2015-02-25 08:55 - 2012-10-09 17:44 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\uTorrent
2015-02-25 08:33 - 2012-01-21 02:18 - 00669116 _____ () C:\windows\system32\perfh005.dat
2015-02-25 08:33 - 2012-01-21 02:18 - 00141744 _____ () C:\windows\system32\perfc005.dat
2015-02-25 08:33 - 2009-07-14 06:13 - 01584554 _____ () C:\windows\system32\PerfStringBackup.INI
2015-02-25 07:43 - 2014-07-19 21:12 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\LogMeIn Hamachi
2015-02-25 07:43 - 2013-10-21 18:41 - 00000000 ____D () C:\Users\Blanka\AppData\Local\LogMeIn Hamachi
2015-02-25 07:43 - 2012-01-21 01:03 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup
2015-02-24 12:08 - 2014-07-21 15:29 - 00000000 ____D () C:\Users\Hoooonza\Documents\Bandicam
2015-02-24 11:07 - 2014-07-21 08:01 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\vlc
2015-02-24 09:43 - 2009-07-14 05:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-24 09:43 - 2009-07-14 05:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-24 09:37 - 2012-01-21 01:13 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2015-02-24 09:37 - 2012-01-21 01:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2015-02-24 09:35 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-02-24 07:05 - 2014-11-18 21:46 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-02-22 15:38 - 2013-11-11 20:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-21 10:20 - 2014-09-16 19:32 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Skype
2015-02-19 16:36 - 2012-10-09 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-02-18 07:54 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-02-17 07:34 - 2014-03-03 17:18 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2015-02-16 18:29 - 2012-07-06 14:39 - 00000000 ____D () C:\Users\Blanka
2015-02-16 16:20 - 2013-11-03 10:17 - 00033856 ____H (LogMeIn, Inc.) C:\windows\system32\hamachi.sys
2015-02-16 08:01 - 2009-07-14 05:45 - 00309160 _____ () C:\windows\system32\FNTCACHE.DAT
2015-02-16 07:58 - 2014-12-10 20:21 - 00000000 ____D () C:\windows\system32\appraiser
2015-02-16 07:58 - 2014-05-08 12:13 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-02-16 07:38 - 2012-07-06 14:48 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-16 07:38 - 2012-07-06 14:48 - 00001912 _____ () C:\windows\epplauncher.mif
2015-02-16 07:37 - 2012-07-06 14:48 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-16 07:37 - 2012-07-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2015-02-16 07:35 - 2013-07-25 22:41 - 00000000 ____D () C:\windows\system32\MRT
2015-02-16 07:28 - 2012-07-06 15:14 - 116773704 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-02-12 13:42 - 2015-01-03 21:41 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2015-02-12 13:42 - 2012-01-21 00:44 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-02-12 13:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-02-12 13:11 - 2012-01-21 01:02 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-12 11:23 - 2015-01-05 07:02 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-02-12 11:21 - 2014-12-18 07:46 - 00003262 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1000
2015-02-12 11:21 - 2012-07-08 13:42 - 00001120 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-12 11:21 - 2012-07-08 13:42 - 00001120 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-12 10:42 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-02-09 14:14 - 2014-12-17 14:07 - 00003284 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1003
2015-02-08 20:20 - 2014-12-22 10:40 - 00002010 _____ () C:\Users\Hoooonza\Desktop\Avast Free Antivirus.lnk
2015-02-08 20:08 - 2014-12-05 19:14 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\osu!
2015-02-06 16:32 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-06 16:03 - 2014-11-18 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-02-06 15:50 - 2014-11-07 18:48 - 00001070 _____ () C:\Users\Hoooonza\Desktop\Bandicam.lnk
2015-02-06 14:13 - 2012-01-21 00:43 - 00000000 ____D () C:\Program Files\Dell
2015-02-06 11:50 - 2014-11-25 09:47 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2015-02-06 11:50 - 2012-07-06 14:39 - 00069816 _____ () C:\Users\Blanka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-06 10:09 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\Web
2015-02-06 10:07 - 2014-10-13 18:08 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-02-05 15:46 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-02-05 14:24 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2015-02-04 20:18 - 2012-07-06 15:00 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 20:18 - 2012-01-21 00:38 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 20:07 - 2014-03-09 20:58 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2015-02-03 20:07 - 2014-03-09 20:34 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2015-02-03 18:20 - 2014-03-09 20:34 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2015-02-03 17:05 - 2015-01-04 10:46 - 00000947 _____ () C:\Users\NightCore\Desktop\osu!.lnk
2015-02-03 14:06 - 2014-09-16 19:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-02-02 21:20 - 2014-03-09 20:11 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-02-01 19:33 - 2014-07-19 21:12 - 00069816 _____ () C:\Users\Hoooonza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-01 18:45 - 2014-09-17 06:26 - 00002436 _____ () C:\Users\Hoooonza\Desktop\Google Chrome.lnk
2015-02-01 18:45 - 2014-07-19 21:11 - 00001605 _____ () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-31 12:06 - 2014-11-04 17:29 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\PunkBuster
2015-01-31 11:48 - 2014-10-11 15:23 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Adobe
2015-01-31 11:23 - 2014-09-16 17:35 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\uTorrent
2015-01-31 10:52 - 2014-03-01 18:57 - 00000000 ____D () C:\Counter-Strike 1.6
2015-01-29 13:53 - 2014-04-01 16:58 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\mctitanpokemine4
2015-01-28 20:57 - 2014-11-18 21:32 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-28 20:29 - 2013-04-09 17:14 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 19:35 - 2014-07-19 21:11 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Adobe
2015-01-28 07:43 - 2012-07-08 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-27 14:36 - 2015-01-02 19:10 - 00000412 _____ () C:\windows\Tasks\SlimDrivers Startup.job
2015-01-27 09:09 - 2015-01-02 19:10 - 00002842 _____ () C:\windows\System32\Tasks\SlimDrivers Startup
2015-01-27 09:09 - 2015-01-02 19:09 - 00016152 _____ () C:\windows\system32\Drivers\SWDUMon.sys
2015-01-27 07:46 - 2014-05-05 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
==================== Files in the root of some directories =======
2015-02-02 20:33 - 2015-02-02 21:34 - 6000640 _____ () C:\Program Files (x86)\GUT523E.tmp
2013-05-05 15:46 - 2013-05-05 15:47 - 139277037 _____ () C:\Users\Blanka\AppData\Roaming\.minecraft.rar
2013-12-08 20:02 - 2013-12-08 20:03 - 339014285 _____ () C:\Users\Blanka\AppData\Roaming\mctitanpokemine.rar
2013-05-05 15:52 - 2013-04-27 11:28 - 94015387 _____ () C:\Users\Blanka\AppData\Roaming\Tropicraft-1.2.5.zip
2014-02-15 10:48 - 2014-09-01 10:52 - 0012288 _____ () C:\Users\Blanka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-26 20:59 - 2015-01-26 20:59 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 12:08
==================== End Of Log ============================
Ran by Blanka (administrator) on BLANKA-PC on 25-02-2015 10:22:11
Running from C:\Users\Blanka\Desktop
Loaded Profiles: Blanka & Hoooonza (Available profiles: Blanka & Hoooonza & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
(Alexander Roshal) C:\Program Files (x86)\WinRAR\WinRAR.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
() C:\Program Files (x86)\Opera\27.0.1689.69\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-02-17] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [reg_svr] => "C:\windows\SysWoW64\regsvr32.exe" /s "C:\Users\Blanka\AppData\Roaming\glister\nvm.dll"
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-11-24] (Glarysoft Ltd)
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Run: [uTorrent] => C:\Users\Blanka\AppData\Roaming\uTorrent\uTorrent.exe [1374032 2015-02-16] (BitTorrent Inc.)
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd)
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\...\MountPoints2: {aee647c9-43be-11e1-aeee-806e6f6e6963} - D:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AdFender.lnk
ShortcutTarget: AdFender.lnk -> C:\Program Files (x86)\AdFender\AdFender.exe (AdFender, Inc.)
Startup: C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk -> C:\Program Files\HP\HP Deskjet 2050 J510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk *
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://isearch.omiga-plus.com/?type=hpp ... XX6WS11HLD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://isearch.omiga-plus.com/web/?type ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://isearch.omiga-plus.com/?type=hpp ... XX6WS11HLD
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/UP97_FRPage
HKU\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=s ... earchTerms}
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-412466861-1309505891-1087973670-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://isearch.omiga-plus.com/web/?type ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1000 -> {E1BFFB17-C02F-4424-9D75-91514E720970} URL = http://search.conduit.com/ResultsExt.as ... 96519&UM=1
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = http://isearch.omiga-plus.com/web/?utm_ ... earchTerms}
SearchScopes: HKU\S-1-5-21-412466861-1309505891-1087973670-1003 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=s ... earchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{D9878FF6-B546-495F-B936-597080B07E0C}: [NameServer] 0.0.0.0
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
FF DefaultSearchEngine: Seznam
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Blanka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1003: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Hoooonza\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-412466861-1309505891-1087973670-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Hoooonza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\omiga-plus.xml
FF SearchPlugin: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\seznam-avast.xml
FF Extension: Seznam lištička - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-05]
FF Extension: Adblock Plus - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-19]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-01-26]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-18]
FF HKLM-x32\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\extensions\fftoolbar2014@etech.com
FF HKU\S-1-5-21-412466861-1309505891-1087973670-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR DefaultSearchKeyword: Profile 1 -> seznam.cz
CHR DefaultSearchURL: Profile 1 -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Profile 1 -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-13]
CHR Extension: (Google Docs) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-13]
CHR Extension: (Google Drive) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-13]
CHR Extension: (YouTube) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-13]
CHR Extension: (Google Search) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-13]
CHR Extension: (Avast SafePrice) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2014-12-18]
CHR Extension: (Google Sheets) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-13]
CHR Extension: (Avast Online Security) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-19]
CHR Extension: (Skype Click to Call) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-02-02]
CHR Extension: (Google Wallet) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-13]
CHR Extension: (Gmail) - C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-13]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Blanka\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-11-21]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [eibfgbclmgnmffinenpipoibfdoblond] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-rv-1.5.4.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fkfpcckoflkdgjdobdkpclgngaahgbpi] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-email-1.3.1.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ghoooididkjbjjldgojdgceoinbhbjmh] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\listicka-chrome-slovnik-1.2.2.crx [2014-07-19]
CHR HKU\S-1-5-21-412466861-1309505891-1087973670-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lelcohngbjgpiibagnfmncojacafbbpg] - C:\Users\Hoooonza\AppData\Roaming\Seznam.cz\bin\Partner-1.1.0.crx [2014-07-19]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-18]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-18]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-18] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-18] (Avast Software)
S3 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [921664 2011-05-19] (Intel Corporation) [File not signed]
S3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1335360 2011-05-19] (Intel Corporation) [File not signed]
S3 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [995392 2011-05-19] (Intel Corporation) [File not signed]
S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-02-16] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-16] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76152 2014-11-04] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 IHProtect Service; C:\Program Files (x86)\XTab\ProtectService.exe [X]
S2 Update Cyti Web; "C:\Program Files (x86)\Cyti Web\updateCytiWeb.exe" [X]
S2 Util Cyti Web; "C:\Program Files (x86)\Cyti Web\bin\utilCytiWeb.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-18] ()
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2015-02-05] (Symantec Corporation)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [20160 2014-11-25] (Glarysoft Ltd)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-25] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2015-01-27] ()
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-18] (Avast Software)
R1 {3560b757-0519-45b3-a215-cfb94afd0821}Gw64; C:\Windows\System32\drivers\{3560b757-0519-45b3-a215-cfb94afd0821}Gw64.sys [48832 2015-02-05] (StdLib)
R1 {4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64; C:\Windows\System32\drivers\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64.sys [48832 2015-02-10] (StdLib)
R1 {c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64; C:\Windows\System32\drivers\{c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64.sys [48832 2015-02-06] (StdLib)
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S2 SPDRIVER_1489.0.0.0; \??\C:\Program Files (x86)\ShopperPro\JSDriver\1489.0.0.0\jsdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 10:22 - 2015-02-25 10:23 - 00028949 _____ () C:\Users\Blanka\Desktop\FRST.txt
2015-02-25 10:21 - 2015-02-25 10:21 - 02087424 _____ (Farbar) C:\Users\Blanka\Desktop\FRST64.exe
2015-02-25 08:40 - 2015-02-25 10:22 - 00000000 ____D () C:\FRST
2015-02-24 19:36 - 2015-02-24 19:36 - 00000000 ____D () C:\Users\Hoooonza\Desktop\NakashiCraft
2015-02-24 19:35 - 2015-02-24 19:35 - 00000000 ____D () C:\Users\Hoooonza\Desktop\Nakashi_pack
2015-02-24 18:04 - 2015-02-24 18:05 - 06855059 _____ () C:\Users\Hoooonza\Downloads\Nakashi_pack1.1.3.rar
2015-02-24 17:49 - 2015-02-24 17:49 - 00000000 ____D () C:\Users\Hoooonza\Documents\Uživatelské soubory aplikace paint.net
2015-02-24 14:36 - 2015-02-24 14:36 - 00038842 _____ () C:\Users\Hoooonza\Desktop\pack.pdn
2015-02-24 14:30 - 2015-02-24 14:30 - 00001202 _____ () C:\Users\Hoooonza\Desktop\paint.net.lnk
2015-02-24 14:17 - 2015-02-24 17:57 - 00000000 ____D () C:\Users\Hoooonza\Desktop\Nový YT pack
2015-02-24 14:17 - 2015-02-24 14:42 - 00000000 ____D () C:\Users\Hoooonza\Desktop\MangaLive
2015-02-24 14:02 - 2015-02-24 14:03 - 04170521 _____ () C:\Users\Hoooonza\Desktop\MyLol.zip
2015-02-24 13:51 - 2015-02-24 13:52 - 00000000 ____D () C:\Users\Hoooonza\Desktop\TextPack
2015-02-24 13:38 - 2015-02-24 13:38 - 00674720 _____ ( ) C:\Users\Hoooonza\Downloads\minecraft-1-5-2-plna-hra
2015-02-24 13:38 - 2015-02-24 13:38 - 00674720 _____ ( ) C:\Users\Hoooonza\Desktop\minecraft-1-5-2-plna-hra
2015-02-24 13:35 - 2015-02-24 13:35 - 00001214 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2015-02-24 13:35 - 2015-02-24 13:35 - 00001202 _____ () C:\Users\Public\Desktop\paint.net.lnk
2015-02-24 13:33 - 2015-02-24 13:35 - 00000000 ____D () C:\Program Files\paint.net
2015-02-24 13:32 - 2015-02-24 13:41 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\paint.net
2015-02-24 13:31 - 2015-02-24 13:31 - 06528454 _____ () C:\Users\Hoooonza\Desktop\paint.net.4.0.5.install.zip
2015-02-24 13:29 - 2015-02-24 13:31 - 06528454 _____ () C:\Users\Hoooonza\Downloads\paint.net.4.0.5.install.zip
2015-02-24 12:39 - 2015-02-20 12:19 - 00000000 ____D () C:\Users\Hoooonza\Desktop\1.5.2BC-extra
2015-02-24 12:36 - 2015-02-24 12:37 - 04760644 _____ () C:\Users\Hoooonza\Downloads\minecrivel (1).zip
2015-02-24 12:35 - 2015-02-24 12:40 - 46738630 _____ () C:\Users\Hoooonza\Desktop\minecraft (2).rar
2015-02-24 12:29 - 2015-02-24 12:30 - 53186993 _____ () C:\Users\Hoooonza\Downloads\minecraft (2).rar
2015-02-24 12:24 - 2015-02-24 12:24 - 04760644 _____ () C:\Users\Hoooonza\Downloads\minecrivel.zip
2015-02-24 11:45 - 2015-02-24 11:57 - 200063578 _____ () C:\Users\Hoooonza\Downloads\Sony-Vegas-Pro-10.0.rar
2015-02-24 11:44 - 2015-02-24 11:44 - 01826135 _____ () C:\Users\Hoooonza\Downloads\Crack-Sony-Vegas-Pro-10.0.rar
2015-02-24 09:46 - 2015-02-24 12:06 - 00000000 ____D () C:\Users\Hoooonza\Desktop\You
2015-02-24 09:40 - 2015-02-24 09:40 - 00000574 _____ () C:\Users\Hoooonza\Desktop\Fraps.lnk
2015-02-24 09:40 - 2015-02-24 09:40 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
2015-02-24 09:38 - 2015-02-24 09:38 - 00000197 _____ () C:\windows\system32\2015-02-24-08-38-50.076-AvastVBoxSVC.exe-3796.log
2015-02-24 07:48 - 2015-02-24 07:48 - 00022588 _____ () C:\Users\Hoooonza\Desktop\hs_err_pid5536.log
2015-02-24 07:08 - 2015-02-24 07:08 - 00000197 _____ () C:\windows\system32\2015-02-24-06-08-04.057-AvastVBoxSVC.exe-4412.log
2015-02-23 11:15 - 2015-02-23 11:16 - 00000197 _____ () C:\windows\system32\2015-02-23-10-15-55.073-AvastVBoxSVC.exe-3344.log
2015-02-22 16:06 - 2015-02-22 16:06 - 00000000 ____D () C:\windows\SysWOW64\Adobe
2015-02-22 16:05 - 2015-02-22 16:06 - 05007216 _____ (Adobe Systems Inc.) C:\Users\Blanka\Downloads\Shockwave_Installer_Slim.exe
2015-02-22 16:02 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer (2).exe
2015-02-22 16:02 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer (1).exe
2015-02-22 16:02 - 2015-02-22 16:02 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Unity
2015-02-22 16:01 - 2015-02-22 16:02 - 03249480 _____ (Unity Technologies ApS) C:\Users\Blanka\Downloads\UnityWebPlayer.exe
2015-02-22 15:53 - 2015-02-22 15:53 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\.minecraft
2015-02-22 15:53 - 2015-02-22 15:52 - 53186993 _____ () C:\Users\Blanka\Desktop\minecraft.rar
2015-02-22 15:52 - 2015-02-22 15:52 - 53186993 _____ () C:\Users\Blanka\Downloads\minecraft.rar
2015-02-22 15:38 - 2015-02-22 15:38 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Steam
2015-02-21 12:07 - 2015-02-21 12:07 - 00000197 _____ () C:\windows\system32\2015-02-21-11-07-02.030-AvastVBoxSVC.exe-4588.log
2015-02-21 09:12 - 2015-02-21 09:12 - 00002144 _____ () C:\Users\Hoooonza\Desktop\Minecraft.lnk
2015-02-21 09:12 - 2015-02-21 09:12 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-02-21 09:11 - 2015-02-21 09:12 - 11995143 _____ () C:\Users\Hoooonza\Downloads\CraftBukkit-1.5.2.rar
2015-02-21 08:58 - 2015-02-21 09:10 - 115388610 _____ () C:\Users\Hoooonza\Downloads\Minecraft-1.7.2.-na-100%-funguje-.rar
2015-02-21 08:55 - 2015-02-21 08:56 - 11012464 _____ () C:\Users\Hoooonza\Downloads\Minecraft-1.7.2.rar
2015-02-21 08:45 - 2015-02-24 19:37 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\.minecraft
2015-02-21 08:00 - 2015-02-21 08:00 - 00002257 _____ () C:\Users\Hoooonza\Documents\Můj film.wlmp
2015-02-21 07:46 - 2015-02-21 07:47 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{16F58C8B-951F-4E17-B3B9-700B1C2558F6}
2015-02-21 07:12 - 2015-02-21 07:13 - 51714155 _____ () C:\Users\Hoooonza\Downloads\minecraft.rar
2015-02-21 06:59 - 2015-02-24 11:11 - 00000000 ____D () C:\Users\Hoooonza\Desktop\New
2015-02-21 06:59 - 2015-02-21 06:59 - 51714155 _____ () C:\Users\Hoooonza\Downloads\minecraft (1).rar
2015-02-21 06:57 - 2015-02-21 06:57 - 00000197 _____ () C:\windows\system32\2015-02-21-05-57-02.065-AvastVBoxSVC.exe-3932.log
2015-02-20 14:21 - 2015-02-20 14:27 - 05564661 _____ () C:\Users\Hoooonza\Downloads\minecraft.jar
2015-02-20 13:49 - 2015-02-20 13:49 - 00000197 _____ () C:\windows\system32\2015-02-20-12-49-27.021-AvastVBoxSVC.exe-4212.log
2015-02-20 07:48 - 2015-02-20 07:49 - 00000197 _____ () C:\windows\system32\2015-02-20-06-48-56.040-AvastVBoxSVC.exe-3088.log
2015-02-19 17:46 - 2015-02-24 17:51 - 00000693 _____ () C:\Users\Hoooonza\Desktop\Čarovný-Minecraft-1.5.2.lnk
2015-02-19 17:16 - 2015-02-19 17:16 - 00000946 _____ () C:\Users\Hoooonza\Desktop\LogMeIn Hamachi.lnk
2015-02-19 17:10 - 2015-02-19 17:22 - 108060963 _____ () C:\Users\Hoooonza\Downloads\Čarovný-Minecraft-1.5.2.rar
2015-02-19 07:21 - 2015-02-19 07:21 - 00000197 _____ () C:\windows\system32\2015-02-19-06-21-05.044-AvastVBoxSVC.exe-3680.log
2015-02-19 07:19 - 2015-02-19 07:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-02-19 07:19 - 2015-02-19 07:19 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-02-18 17:55 - 2015-02-18 17:55 - 00002778 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2015-02-18 07:27 - 2015-02-18 07:27 - 00000197 _____ () C:\windows\system32\2015-02-18-06-27-44.039-AvastVBoxSVC.exe-4256.log
2015-02-17 16:33 - 2015-02-17 16:34 - 05054184 _____ () C:\Users\Blanka\Desktop\Nodus-1.5.2.rar
2015-02-17 07:44 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-02-17 07:44 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-02-17 07:44 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-02-17 07:44 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-02-16 18:55 - 2015-02-22 15:54 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-02-16 18:54 - 2015-02-16 18:54 - 00016948 _____ () C:\Users\Blanka\Downloads\[CzT]Minecraft_1_7_2_2013_CZ_.torrent
2015-02-16 08:04 - 2015-02-16 08:04 - 00000197 _____ () C:\windows\system32\2015-02-16-07-04-28.005-AvastVBoxSVC.exe-3660.log
2015-02-16 08:01 - 2015-02-25 08:32 - 00001350 _____ () C:\windows\setupact.log
2015-02-16 08:01 - 2015-02-16 08:01 - 00000000 _____ () C:\windows\setuperr.log
2015-02-16 07:59 - 2015-02-16 07:59 - 00000766 _____ () C:\windows\PFRO.log
2015-02-12 13:11 - 2015-02-25 08:27 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-02-12 13:11 - 2015-02-12 13:11 - 00002021 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-02-12 11:34 - 2015-02-12 11:34 - 02347384 _____ (ESET) C:\Users\Blanka\Desktop\esetsmartinstaller_csy (1).exe
2015-02-12 11:23 - 2015-02-12 11:23 - 00003824 _____ () C:\windows\System32\Tasks\Opera scheduled Autoupdate 1420437773
2015-02-12 10:43 - 2015-02-12 10:43 - 00000197 _____ () C:\windows\system32\2015-02-12-09-43-54.047-AvastVBoxSVC.exe-4776.log
2015-02-12 10:25 - 2015-02-25 08:50 - 00000000 ____D () C:\Program Files\trend micro
2015-02-11 18:03 - 2015-02-11 18:03 - 00000197 _____ () C:\windows\system32\2015-02-11-17-03-47.032-AvastVBoxSVC.exe-3664.log
2015-02-11 10:10 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-02-11 10:10 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-02-11 10:10 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-02-11 10:09 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-02-11 10:09 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2015-02-11 10:09 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-02-11 10:09 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-02-11 10:09 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-02-11 10:09 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-02-11 10:09 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-02-11 10:09 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-02-11 10:09 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-02-11 10:09 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-02-11 10:09 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-02-11 10:09 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-02-11 10:09 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-02-11 10:09 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-02-11 10:09 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-02-11 10:09 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-02-11 10:09 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-02-11 10:09 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-02-11 10:09 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-02-11 10:09 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 10:09 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-02-11 10:09 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-02-11 10:09 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-02-11 10:09 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-02-11 10:09 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-02-11 10:09 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-02-11 10:09 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-02-11 10:09 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-02-11 10:09 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-02-11 10:09 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-02-11 10:09 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-02-11 10:09 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-02-11 10:09 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-02-11 10:09 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-02-11 10:09 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-02-11 10:09 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-02-11 10:09 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 10:09 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-02-11 10:09 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-02-11 10:09 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-02-11 10:09 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-02-11 10:09 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-02-11 10:09 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-02-11 10:09 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-02-11 10:09 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-02-11 10:09 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-02-11 10:09 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-02-11 10:09 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-02-11 10:09 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-02-11 10:09 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-02-11 10:09 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-02-11 10:09 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-02-11 10:08 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-02-11 10:08 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-02-11 10:08 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-02-11 10:08 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-02-11 10:08 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-02-11 10:08 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-02-11 10:08 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-02-11 10:08 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-02-11 10:08 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-02-11 10:08 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-02-11 10:08 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-02-11 10:08 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-02-11 10:08 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-02-11 10:08 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-02-11 10:08 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-02-11 10:08 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-02-11 10:08 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2015-02-11 10:08 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2015-02-11 10:08 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2015-02-11 10:08 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2015-02-11 10:08 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2015-02-11 10:08 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2015-02-11 10:08 - 2014-10-04 03:10 - 03722752 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-02-11 10:08 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-02-11 10:08 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2015-02-11 10:08 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2015-02-11 10:08 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2015-02-11 10:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2015-02-11 10:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2015-02-11 10:07 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-02-11 10:07 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-02-11 10:07 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-02-11 10:07 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-02-11 10:07 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-02-11 10:07 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-02-11 10:07 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-02-11 10:07 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll
2015-02-11 10:07 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\windows\SysWOW64\scesrv.dll
2015-02-11 10:06 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-02-11 09:55 - 2015-02-11 09:55 - 00000197 _____ () C:\windows\system32\2015-02-11-08-55-44.028-AvastVBoxSVC.exe-3984.log
2015-02-10 18:20 - 2015-02-10 01:29 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}Gw64.sys
2015-02-10 10:55 - 2015-02-10 10:55 - 00183090 _____ () C:\Users\Blanka\Downloads\00322924-01-2015-EVP.zip
2015-02-10 10:20 - 2015-02-10 10:20 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\AVG
2015-02-10 10:18 - 2015-02-10 10:18 - 00000000 ____D () C:\Users\Blanka\AppData\Local\Avg
2015-02-09 14:28 - 2015-02-09 14:28 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\AVG
2015-02-09 14:27 - 2015-02-09 14:27 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Avg
2015-02-09 14:27 - 2015-02-09 14:27 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-02-09 14:25 - 2015-02-21 07:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-02-09 14:25 - 2015-02-09 14:29 - 00000000 ____D () C:\ProgramData\AVG
2015-02-09 14:25 - 2015-02-09 14:27 - 00000000 ____D () C:\Users\Hoooonza\Documents\Freemake
2015-02-09 14:25 - 2015-02-09 14:26 - 00000000 ____D () C:\ProgramData\Freemake
2015-02-09 14:25 - 2015-02-09 14:25 - 00001340 _____ () C:\Users\Hoooonza\Desktop\Freemake Video Converter.lnk
2015-02-09 14:25 - 2015-02-09 14:25 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-02-09 14:23 - 2015-02-09 14:25 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-02-09 14:23 - 2015-02-09 14:23 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\RHEng
2015-02-09 14:20 - 2015-02-09 14:20 - 08042929 _____ () C:\Users\Hoooonza\Downloads\FreemakeVideoConverter-setup.exe
2015-02-08 20:10 - 2015-02-08 20:10 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{DC4AFAF8-92FD-42E6-BB9D-947156889420}
2015-02-08 19:52 - 2015-02-08 19:54 - 20074891 _____ () C:\Users\Hoooonza\Downloads\52361 Skillet - Hero.osz
2015-02-08 19:51 - 2015-02-08 19:51 - 07322524 _____ () C:\Users\Hoooonza\Downloads\13835 Iyaz - Replay.osz
2015-02-08 19:12 - 2015-02-16 08:01 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-08 19:12 - 2015-02-16 08:01 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-08 19:12 - 2015-02-12 11:18 - 00003960 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-08 19:12 - 2015-02-12 11:18 - 00003708 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-08 19:10 - 2015-02-08 19:10 - 00000197 _____ () C:\windows\system32\2015-02-08-18-10-10.054-AvastVBoxSVC.exe-3972.log
2015-02-07 15:25 - 2015-02-12 11:19 - 00000000 ____D () C:\Users\Blanka\AppData\Local\CrashDumps
2015-02-07 15:24 - 2015-02-07 15:24 - 00000197 _____ () C:\windows\system32\2015-02-07-14-24-12.098-AvastVBoxSVC.exe-4072.log
2015-02-07 15:24 - 2015-02-06 19:34 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{c0915853-fd66-4086-a9ce-b80496d49b3f}Gw64.sys
2015-02-06 15:41 - 2015-02-06 15:41 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\AdFender
2015-02-06 14:09 - 2015-02-06 14:09 - 00000000 ____D () C:\Users\NightCore\AppData\Local\LogMeIn
2015-02-06 14:09 - 2015-02-06 14:09 - 00000000 ____D () C:\Users\NightCore\AppData\Local\AdFender
2015-02-06 12:01 - 2015-02-06 12:01 - 00000000 ____D () C:\ProgramData\GlarySoft
2015-02-06 11:04 - 2015-02-06 11:04 - 00001366 _____ () C:\Users\Blanka\Desktop\CCleaner – zástupce.lnk
2015-02-06 10:25 - 2015-02-06 10:26 - 00000000 ____D () C:\Users\Blanka\AppData\Local\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\ProgramData\AdFender
2015-02-06 10:25 - 2015-02-06 10:25 - 00000000 ____D () C:\Program Files (x86)\AdFender
2015-02-06 10:12 - 2015-02-05 17:29 - 00048832 _____ (StdLib) C:\windows\system32\Drivers\{3560b757-0519-45b3-a215-cfb94afd0821}Gw64.sys
2015-02-06 09:14 - 2015-02-25 09:02 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-06 09:14 - 2015-02-12 11:05 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-02-06 09:14 - 2015-02-06 09:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-06 09:14 - 2015-02-06 09:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-06 09:14 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-02-06 09:14 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-02-05 15:52 - 2015-02-19 08:56 - 00000460 ____H () C:\windows\Tasks\Norton Security Scan for NightCore.job
2015-02-05 15:52 - 2015-02-05 15:52 - 00003628 _____ () C:\windows\System32\Tasks\Norton Security Scan for NightCore
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\windows\system32\Drivers\NSSx64
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\ProgramData\Norton
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
2015-02-05 15:52 - 2015-02-05 15:52 - 00000000 ____D () C:\Program Files (x86)\Norton Security Scan
2015-02-05 15:51 - 2015-02-05 15:51 - 00001921 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\WeatherBug®.lnk
2015-02-05 15:51 - 2015-02-05 15:51 - 00001897 _____ () C:\Users\NightCore\Desktop\WeatherBug®.lnk
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\Users\NightCore\AppData\Local\IsolatedStorage
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®
2015-02-05 15:51 - 2015-02-05 15:51 - 00000000 ____D () C:\Program Files\Earth Networks
2015-02-05 15:50 - 2015-02-05 15:51 - 00000000 __HDC () C:\ProgramData\{FA77A43D-F6ED-4924-87B5-517C061388C6}
2015-02-05 15:49 - 2015-02-05 15:49 - 00675988 _____ () C:\Users\NightCore\Desktop\minecraft.exe.EXE
2015-02-05 15:49 - 2015-02-05 15:49 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online
2015-02-05 15:49 - 2015-02-05 15:49 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\ImperiaOnline
2015-02-05 14:26 - 2015-02-05 14:26 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\.minecraft
2015-02-04 21:04 - 2015-02-04 21:05 - 03386604 _____ () C:\Users\NightCore\Downloads\42481 Eiffel 65 - I'm Blue (Da Ba Dee).osz
2015-02-04 20:59 - 2015-02-04 20:59 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\vlc
2015-02-04 20:58 - 2015-02-04 21:01 - 00000000 ____D () C:\Users\NightCore\Documents\Kawaii
2015-02-03 20:16 - 2015-02-03 20:19 - 00002443 _____ () C:\Users\NightCore\Desktop\Anime.lnk
2015-02-03 20:13 - 2015-02-03 20:13 - 00014110 ____H () C:\Users\NightCore\Desktop\photoshop – zástupce.lnk
2015-02-03 18:04 - 2015-02-03 18:04 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001 (2)
2015-02-03 18:03 - 2015-02-03 18:03 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001 (1)
2015-02-03 18:03 - 2015-02-03 18:03 - 00045653 _____ () C:\Users\NightCore\Downloads\4696001
2015-02-03 17:17 - 2015-02-03 17:17 - 07322524 _____ () C:\Users\NightCore\Downloads\13835 Iyaz - Replay.osz
2015-02-03 17:05 - 2015-02-03 17:05 - 00000955 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2015-02-03 17:03 - 2015-02-06 14:28 - 00000000 ____D () C:\Users\NightCore\AppData\Local\osu!
2015-02-03 15:58 - 2015-02-03 15:58 - 00069816 _____ () C:\Users\NightCore\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-03 14:06 - 2015-02-03 21:41 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Skype
2015-02-03 14:06 - 2015-02-03 14:06 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Skype
2015-02-03 14:03 - 2015-02-06 16:02 - 00000000 ____D () C:\Users\NightCore\AppData\Local\LogMeIn Hamachi
2015-02-03 14:03 - 2015-02-03 14:03 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\IDT
2015-02-02 22:32 - 2015-02-02 22:32 - 00000000 ____D () C:\Users\NightCore\Documents\Tiskárna
2015-02-02 21:42 - 2015-02-02 21:42 - 00000000 ____D () C:\Users\NightCore\AppData\Local\HP
2015-02-02 21:38 - 2015-02-02 21:38 - 00000000 ____D () C:\Users\NightCore\AppData\Local\PunkBuster
2015-02-02 21:27 - 2015-02-02 22:33 - 00000000 ____D () C:\Users\NightCore\Documents\Battlefield Play4Free
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Mozilla
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Mozilla
2015-02-02 21:07 - 2015-02-02 21:07 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Macromedia
2015-02-02 21:00 - 2015-02-02 21:00 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Windows Live
2015-02-02 21:00 - 2015-02-02 21:00 - 00000000 ____D () C:\Users\NightCore\AppData\Local\{BF7B76A3-486A-4C14-B69B-4809DF2B454E}
2015-02-02 20:58 - 2015-02-02 20:58 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\WinRAR
2015-02-02 20:40 - 2015-02-02 20:40 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\AVAST Software
2015-02-02 20:39 - 2015-02-02 21:17 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-02 20:39 - 2015-02-02 20:44 - 00002310 _____ () C:\Users\NightCore\Desktop\Google Chrome.lnk
2015-02-02 20:39 - 2015-02-02 20:39 - 00001395 _____ () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-02 20:39 - 2015-02-02 20:39 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Adobe
2015-02-02 20:38 - 2015-02-02 20:38 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Intel
2015-02-02 20:38 - 2015-02-02 20:38 - 00000000 ____D () C:\Users\NightCore\AppData\Local\VirtualStore
2015-02-02 20:37 - 2015-02-03 14:03 - 00000000 ____D () C:\Users\NightCore\AppData\Local\SoftThinks
2015-02-02 20:37 - 2015-02-02 23:21 - 00000000 ____D () C:\Users\NightCore\AppData\Local\Google
2015-02-02 20:37 - 2015-02-02 20:39 - 00000000 ____D () C:\Users\NightCore
2015-02-02 20:37 - 2015-02-02 20:37 - 00000020 ___SH () C:\Users\NightCore\ntuser.ini
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Šablony
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Soubory cookie
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Poslední
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Okolní tiskárny
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Okolní síť
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Nabídka Start
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Dokumenty
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Obrázky
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Hudba
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Documents\Filmy
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\Data aplikací
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-02-02 20:37 - 2015-02-02 20:37 - 00000000 _SHDL () C:\Users\NightCore\AppData\Local\Data aplikací
2015-02-02 20:37 - 2012-01-21 00:44 - 00000000 ____D () C:\Users\NightCore\AppData\Roaming\Macromedia
2015-02-02 20:37 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-02 20:37 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-02-02 20:33 - 2015-02-02 21:34 - 06000640 _____ () C:\Program Files (x86)\GUT523E.tmp
2015-02-02 20:33 - 2015-02-02 20:33 - 00000000 ____D () C:\Program Files (x86)\GUM522D.tmp
2015-02-02 20:32 - 2015-02-02 20:32 - 00880784 _____ (Google Inc.) C:\Users\Blanka\Downloads\ChromeSetup.exe
2015-02-01 18:48 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\Cyti Web
2015-02-01 18:48 - 2015-02-01 18:48 - 00000000 ____D () C:\ProgramData\IHProtectUpDate
2015-02-01 18:47 - 2015-02-25 07:42 - 00001348 _____ () C:\windows\Tasks\UERRV.job
2015-02-01 18:47 - 2015-02-12 13:43 - 00000000 ____D () C:\Program Files (x86)\XTab
2015-02-01 18:47 - 2015-02-01 18:47 - 00004382 _____ () C:\windows\System32\Tasks\UERRV
2015-02-01 18:46 - 2015-02-25 07:58 - 00001350 _____ () C:\windows\Tasks\CIIAYI.job
2015-02-01 18:46 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\b293b0ed-4515-48e8-8fd9-956160943535
2015-02-01 18:46 - 2015-02-12 13:42 - 00000000 ____D () C:\Program Files (x86)\1acf32df-b1fe-4175-996d-52aaa728b99a
2015-02-01 18:46 - 2015-02-01 18:46 - 00004384 _____ () C:\windows\System32\Tasks\CIIAYI
2015-02-01 18:46 - 2015-02-01 18:46 - 00003730 _____ () C:\windows\System32\Tasks\SMupdate1
2015-02-01 18:46 - 2015-02-01 18:46 - 00003590 _____ () C:\windows\System32\Tasks\YTDownloader
2015-02-01 18:46 - 2015-02-01 18:46 - 00003580 _____ () C:\windows\System32\Tasks\YTDownloaderUpd
2015-02-01 18:46 - 2015-02-01 18:46 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
2015-02-01 18:46 - 2015-02-01 18:46 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\globalUpdate
2015-02-01 18:45 - 2015-02-12 13:43 - 00000000 ____D () C:\Program Files (x86)\YTDownloader
2015-02-01 18:45 - 2015-02-02 13:59 - 00000000 ____D () C:\Program Files (x86)\ShopperPro
2015-02-01 18:45 - 2015-02-01 18:45 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\CrashRpt
2015-01-31 15:22 - 2015-01-31 19:40 - 00000000 ____D () C:\Users\Hoooonza\Documents\Battlefield Play4Free
2015-01-30 19:02 - 2015-01-30 19:02 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Unity
2015-01-30 18:36 - 2015-01-30 18:36 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Unity
2015-01-30 18:04 - 2015-01-30 18:04 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\by_dekart811
2015-01-30 16:04 - 2015-01-30 16:04 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\AVAST Software
2015-01-30 14:58 - 2015-01-30 14:58 - 00002996 _____ () C:\windows\System32\Tasks\{048314BC-FED5-4D79-8976-AE33D3EDBB9E}
2015-01-30 14:54 - 2015-01-30 14:55 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{D65FEFB8-0AD0-482D-9F0E-EEAE617043C6}
2015-01-29 22:40 - 2015-01-29 22:40 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{4357E4C1-4F2B-4B7E-BB2D-70688718B650}
2015-01-29 20:44 - 2015-02-09 14:17 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\CrashDumps
2015-01-29 14:03 - 2014-08-25 16:05 - 01592398 _____ (TeamExtreme) C:\Users\Guest\Desktop\Minecraft.exe
2015-01-28 21:02 - 2015-01-28 21:02 - 00003152 _____ () C:\windows\System32\Tasks\{EEA8F421-702C-4D7C-914F-33ED104F5652}
2015-01-28 21:01 - 2015-02-22 19:43 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\mctpokemine
2015-01-28 20:50 - 2015-01-28 20:50 - 00001366 _____ () C:\Users\Hoooonza\Desktop\CCleaner – zástupce.lnk
2015-01-28 20:33 - 2015-01-28 20:32 - 00320424 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00189352 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00189352 _____ (Oracle Corporation) C:\Users\Hoooonza\Desktop\java.exe
2015-01-28 20:32 - 2015-01-28 20:32 - 00111016 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2015-01-28 20:30 - 2015-01-28 20:29 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2015-01-28 20:29 - 2015-01-28 20:29 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-28 07:53 - 2015-02-06 14:05 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 07:53 - 2015-02-06 11:06 - 00003854 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-27 17:01 - 2015-01-27 17:02 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\{F5299567-2588-4D4A-AE5B-08082A2551FC}
2015-01-27 07:43 - 2015-01-27 07:43 - 00000197 _____ () C:\windows\system32\2015-01-27-06-43-06.099-AvastVBoxSVC.exe-4136.log
2015-01-27 07:43 - 2015-01-27 07:43 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2015-01-27 07:43 - 2015-01-27 07:43 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_09_00.Wdf
2015-01-26 21:04 - 2015-01-26 21:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 20:59 - 2015-01-26 21:05 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000057 _____ () C:\ProgramData\Ament.ini
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\ProgramData\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\Program Files\HP
2015-01-26 20:59 - 2015-01-26 20:59 - 00000000 ____D () C:\Program Files (x86)\HP
2015-01-26 20:48 - 2015-01-26 20:48 - 00000197 _____ () C:\windows\system32\2015-01-26-19-48-03.086-AvastVBoxSVC.exe-3876.log
2015-01-26 08:10 - 2015-01-26 08:10 - 00000197 _____ () C:\windows\system32\2015-01-26-07-10-21.043-AvastVBoxSVC.exe-4876.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-25 10:07 - 2012-01-21 00:26 - 01847600 _____ () C:\windows\WindowsUpdate.log
2015-02-25 09:17 - 2014-11-19 09:17 - 00000000 ____D () C:\Users\Blanka\Desktop\čističe
2015-02-25 08:55 - 2012-10-09 17:44 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\uTorrent
2015-02-25 08:33 - 2012-01-21 02:18 - 00669116 _____ () C:\windows\system32\perfh005.dat
2015-02-25 08:33 - 2012-01-21 02:18 - 00141744 _____ () C:\windows\system32\perfc005.dat
2015-02-25 08:33 - 2009-07-14 06:13 - 01584554 _____ () C:\windows\system32\PerfStringBackup.INI
2015-02-25 07:43 - 2014-07-19 21:12 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\LogMeIn Hamachi
2015-02-25 07:43 - 2013-10-21 18:41 - 00000000 ____D () C:\Users\Blanka\AppData\Local\LogMeIn Hamachi
2015-02-25 07:43 - 2012-01-21 01:03 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup
2015-02-24 12:08 - 2014-07-21 15:29 - 00000000 ____D () C:\Users\Hoooonza\Documents\Bandicam
2015-02-24 11:07 - 2014-07-21 08:01 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\vlc
2015-02-24 09:43 - 2009-07-14 05:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-24 09:43 - 2009-07-14 05:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-24 09:37 - 2012-01-21 01:13 - 00000000 ____D () C:\Users\Default\AppData\Local\SoftThinks
2015-02-24 09:37 - 2012-01-21 01:13 - 00000000 ____D () C:\Users\Default User\AppData\Local\SoftThinks
2015-02-24 09:35 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-02-24 07:05 - 2014-11-18 21:46 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2015-02-22 15:38 - 2013-11-11 20:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-21 10:20 - 2014-09-16 19:32 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Skype
2015-02-19 16:36 - 2012-10-09 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-02-18 07:54 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2015-02-17 07:34 - 2014-03-03 17:18 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2015-02-16 18:29 - 2012-07-06 14:39 - 00000000 ____D () C:\Users\Blanka
2015-02-16 16:20 - 2013-11-03 10:17 - 00033856 ____H (LogMeIn, Inc.) C:\windows\system32\hamachi.sys
2015-02-16 08:01 - 2009-07-14 05:45 - 00309160 _____ () C:\windows\system32\FNTCACHE.DAT
2015-02-16 07:58 - 2014-12-10 20:21 - 00000000 ____D () C:\windows\system32\appraiser
2015-02-16 07:58 - 2014-05-08 12:13 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-02-16 07:38 - 2012-07-06 14:48 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-16 07:38 - 2012-07-06 14:48 - 00001912 _____ () C:\windows\epplauncher.mif
2015-02-16 07:37 - 2012-07-06 14:48 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-16 07:37 - 2012-07-06 14:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2015-02-16 07:35 - 2013-07-25 22:41 - 00000000 ____D () C:\windows\system32\MRT
2015-02-16 07:28 - 2012-07-06 15:14 - 116773704 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-02-12 13:42 - 2015-01-03 21:41 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2015-02-12 13:42 - 2012-01-21 00:44 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-02-12 13:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-02-12 13:11 - 2012-01-21 01:02 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-12 11:23 - 2015-01-05 07:02 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-02-12 11:21 - 2014-12-18 07:46 - 00003262 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1000
2015-02-12 11:21 - 2012-07-08 13:42 - 00001120 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-12 11:21 - 2012-07-08 13:42 - 00001120 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-12 10:42 - 2009-07-14 03:34 - 00000505 _____ () C:\windows\win.ini
2015-02-09 14:14 - 2014-12-17 14:07 - 00003284 _____ () C:\windows\System32\Tasks\avastBCLRestartS-1-5-21-412466861-1309505891-1087973670-1003
2015-02-08 20:20 - 2014-12-22 10:40 - 00002010 _____ () C:\Users\Hoooonza\Desktop\Avast Free Antivirus.lnk
2015-02-08 20:08 - 2014-12-05 19:14 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\osu!
2015-02-06 16:32 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-02-06 16:03 - 2014-11-18 21:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-02-06 15:50 - 2014-11-07 18:48 - 00001070 _____ () C:\Users\Hoooonza\Desktop\Bandicam.lnk
2015-02-06 14:13 - 2012-01-21 00:43 - 00000000 ____D () C:\Program Files\Dell
2015-02-06 11:50 - 2014-11-25 09:47 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2015-02-06 11:50 - 2012-07-06 14:39 - 00069816 _____ () C:\Users\Blanka\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-06 10:09 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\Web
2015-02-06 10:07 - 2014-10-13 18:08 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-02-05 15:46 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-02-05 14:24 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2015-02-04 20:18 - 2012-07-06 15:00 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 20:18 - 2012-01-21 00:38 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 20:07 - 2014-03-09 20:58 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.xtr
2015-02-03 20:07 - 2014-03-09 20:34 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2015-02-03 18:20 - 2014-03-09 20:34 - 00282104 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2015-02-03 17:05 - 2015-01-04 10:46 - 00000947 _____ () C:\Users\NightCore\Desktop\osu!.lnk
2015-02-03 14:06 - 2014-09-16 19:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-02-02 21:20 - 2014-03-09 20:11 - 00000000 ____D () C:\Program Files (x86)\EA Games
2015-02-01 19:33 - 2014-07-19 21:12 - 00069816 _____ () C:\Users\Hoooonza\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-01 18:45 - 2014-09-17 06:26 - 00002436 _____ () C:\Users\Hoooonza\Desktop\Google Chrome.lnk
2015-02-01 18:45 - 2014-07-19 21:11 - 00001605 _____ () C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-31 12:06 - 2014-11-04 17:29 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\PunkBuster
2015-01-31 11:48 - 2014-10-11 15:23 - 00000000 ____D () C:\Users\Hoooonza\AppData\Local\Adobe
2015-01-31 11:23 - 2014-09-16 17:35 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\uTorrent
2015-01-31 10:52 - 2014-03-01 18:57 - 00000000 ____D () C:\Counter-Strike 1.6
2015-01-29 13:53 - 2014-04-01 16:58 - 00000000 ____D () C:\Users\Blanka\AppData\Roaming\mctitanpokemine4
2015-01-28 20:57 - 2014-11-18 21:32 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-28 20:29 - 2013-04-09 17:14 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-28 19:35 - 2014-07-19 21:11 - 00000000 ____D () C:\Users\Hoooonza\AppData\Roaming\Adobe
2015-01-28 07:43 - 2012-07-08 13:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-27 14:36 - 2015-01-02 19:10 - 00000412 _____ () C:\windows\Tasks\SlimDrivers Startup.job
2015-01-27 09:09 - 2015-01-02 19:10 - 00002842 _____ () C:\windows\System32\Tasks\SlimDrivers Startup
2015-01-27 09:09 - 2015-01-02 19:09 - 00016152 _____ () C:\windows\system32\Drivers\SWDUMon.sys
2015-01-27 07:46 - 2014-05-05 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
==================== Files in the root of some directories =======
2015-02-02 20:33 - 2015-02-02 21:34 - 6000640 _____ () C:\Program Files (x86)\GUT523E.tmp
2013-05-05 15:46 - 2013-05-05 15:47 - 139277037 _____ () C:\Users\Blanka\AppData\Roaming\.minecraft.rar
2013-12-08 20:02 - 2013-12-08 20:03 - 339014285 _____ () C:\Users\Blanka\AppData\Roaming\mctitanpokemine.rar
2013-05-05 15:52 - 2013-04-27 11:28 - 94015387 _____ () C:\Users\Blanka\AppData\Roaming\Tropicraft-1.2.5.zip
2014-02-15 10:48 - 2014-09-01 10:52 - 0012288 _____ () C:\Users\Blanka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-26 20:59 - 2015-01-26 20:59 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-23 12:08
==================== End Of Log ============================
Re: Prosím o kontrolu
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Po spusteni probehne stazeni databaze
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; resethosts; emptyclsid; IEdefaults; FFdefaults; CHRdefaults; emptyIEcache; emptyFFcache; emptyCHRcache; emptyalltemp; emptyflash; emptyjava; emptyrecycle.bin;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
-
zdenek72
- 3. Stupeň Varování
- Příspěvky: 106
- Registrován: 09 úno 2010 15:18
- Bydliště: Plzen, Czech Republic
- Kontaktovat uživatele:
Re: Prosím o kontrolu
# AdwCleaner v4.111 - Logfile created 25/02/2015 at 12:04:00
# Updated 18/02/2015 by Xplode
# Database : 2015-02-18.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Blanka - BLANKA-PC
# Running from : C:\Users\Blanka\Desktop\adwcleaner_4.111.exe
# Option : Cleaning
***** [ Services ] *****
Service Deleted : sbmntr
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\ShopperPro
Folder Deleted : C:\Program Files (x86)\YTDownloader
Folder Deleted : C:\Program Files (x86)\GotClip
Folder Deleted : C:\Users\Blanka\AppData\Local\Conduit
Folder Deleted : C:\Users\Blanka\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Blanka\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Blanka\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Blanka\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GotClip
Folder Deleted : C:\Users\Blanka\Documents\Mobogenie
Folder Deleted : C:\Users\Hoooonza\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Hoooonza\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\RHEng
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Deleted : C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh
Folder Deleted : C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
File Deleted : C:\Users\Blanka\daemonprocess.txt
File Deleted : C:\Users\Guest\daemonprocess.txt
File Deleted : C:\Users\Hoooonza\daemonprocess.txt
File Deleted : C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\bingp.xml
File Deleted : C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\user.js
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Scheduled tasks ] *****
Task Deleted : BackgroundContainer Startup Task
Task Deleted : SMupdate1
Task Deleted : SPDriver
Task Deleted : YTDownloader
Task Deleted : YTDownloaderUpd
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E1BFFB17-C02F-4424-9D75-91514E720970}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Speedchecker Limited
Key Deleted : HKCU\Software\YTDownloader
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\MediaViewV1
Key Deleted : HKLM\SOFTWARE\MediaWatchV1
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Sense
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\YTDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5613512-E9DC-6468-9312-B2EC2D6B04F4}_is1
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
Key Deleted : [x64] HKLM\SOFTWARE\YTDownloader
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v35.0.1 (x86 cs)
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("CT3289075.smartbar.homepage", "true");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.bing.com/search?FORM=UP22DF&PC=UP22&dt=041113&q=");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.alias", "omiga-plus");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://isearch.omiga-plus.com/web/favicon.ico");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.name", "omiga-plus");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%22im[...]
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls[...]
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289075&CUI=UN41026820461569515&UM=1&SearchSource=13");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN41026820461569515&UM=1&q=");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.machineId", "RYWCB7KONXQEIIKHFCEDJPHNMNJPGZMYNB0F5BOAQUGHWHRDDNOIABCUR+VX5BPTW1CVINX42AQC3SCFYZFX0G");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.alias", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://isearch.omiga-plus.com/web/favicon.ico");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.name", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3A971100%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.Resources_resource_971109.value", "%22function%20startAskCom%28e%2Ct%2Cr%29%7Bfunction%20a%28e%29%7Bvar%20t%3Dnew%20RegEx[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%2[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.ae9d197d59f2f45f382b1aa5c14d828706aaed9b904554b5cb7984e9com70299.70299.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%22im[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls[...]
-\\ Google Chrome v40.0.2214.115
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
-\\ Opera v27.0.1689.76
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
*************************
AdwCleaner[R0].txt - [13462 bytes] - [25/02/2015 11:38:29]
AdwCleaner[R1].txt - [13522 bytes] - [25/02/2015 11:47:45]
AdwCleaner[S0].txt - [14511 bytes] - [25/02/2015 12:04:00]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14571 bytes] ##########
# Updated 18/02/2015 by Xplode
# Database : 2015-02-18.3 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Blanka - BLANKA-PC
# Running from : C:\Users\Blanka\Desktop\adwcleaner_4.111.exe
# Option : Cleaning
***** [ Services ] *****
Service Deleted : sbmntr
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\ShopperPro
Folder Deleted : C:\Program Files (x86)\YTDownloader
Folder Deleted : C:\Program Files (x86)\GotClip
Folder Deleted : C:\Users\Blanka\AppData\Local\Conduit
Folder Deleted : C:\Users\Blanka\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Blanka\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Blanka\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Blanka\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GotClip
Folder Deleted : C:\Users\Blanka\Documents\Mobogenie
Folder Deleted : C:\Users\Hoooonza\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Hoooonza\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\RHEng
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
Folder Deleted : C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Deleted : C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh
Folder Deleted : C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh
Folder Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
File Deleted : C:\Users\Blanka\daemonprocess.txt
File Deleted : C:\Users\Guest\daemonprocess.txt
File Deleted : C:\Users\Hoooonza\daemonprocess.txt
File Deleted : C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\searchplugins\bingp.xml
File Deleted : C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\user.js
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Scheduled tasks ] *****
Task Deleted : BackgroundContainer Startup Task
Task Deleted : SMupdate1
Task Deleted : SPDriver
Task Deleted : YTDownloader
Task Deleted : YTDownloaderUpd
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E1BFFB17-C02F-4424-9D75-91514E720970}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Speedchecker Limited
Key Deleted : HKCU\Software\YTDownloader
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\MediaViewV1
Key Deleted : HKLM\SOFTWARE\MediaWatchV1
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Sense
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\YTDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5613512-E9DC-6468-9312-B2EC2D6B04F4}_is1
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
Key Deleted : [x64] HKLM\SOFTWARE\YTDownloader
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v35.0.1 (x86 cs)
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("CT3289075.smartbar.homepage", "true");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.bing.com/search?FORM=UP22DF&PC=UP22&dt=041113&q=");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.alias", "omiga-plus");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://isearch.omiga-plus.com/web/favicon.ico");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.name", "omiga-plus");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%22im[...]
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls[...]
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289075&CUI=UN41026820461569515&UM=1&SearchSource=13");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN41026820461569515&UM=1&q=");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3289075");
[z43atfmt.default\prefs.js] - Line Deleted : user_pref("smartbar.machineId", "RYWCB7KONXQEIIKHFCEDJPHNMNJPGZMYNB0F5BOAQUGHWHRDDNOIABCUR+VX5BPTW1CVINX42AQC3SCFYZFX0G");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.alias", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.iconURL", "hxxp://isearch.omiga-plus.com/web/favicon.ico");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.name", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.searchengine.url", "hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "omiga-plus");
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3A971100%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.Resources_resource_971109.value", "%22function%20startAskCom%28e%2Ct%2Cr%29%7Bfunction%20a%28e%29%7Bvar%20t%3Dnew%20RegEx[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.aPDVDZDW52397720XDDWJXW57740856com69795.69795.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%2[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.ae9d197d59f2f45f382b1aa5c14d828706aaed9b904554b5cb7984e9com70299.70299.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.Resources_meta.value", "%7B%22images/icon_255x255.png%22%3A%7B%22id%22%3A750126%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%22im[...]
[pi030hzt.default\prefs.js] - Line Deleted : user_pref("extensions.asepherdwilburaolcom61752.61752.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22urls[...]
-\\ Google Chrome v40.0.2214.115
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
-\\ Opera v27.0.1689.76
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
[C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1422812784&from=obw&uid=ST9750420AS_6WS11HLDXXXX6WS11HLD&q={searchTerms}
*************************
AdwCleaner[R0].txt - [13462 bytes] - [25/02/2015 11:38:29]
AdwCleaner[R1].txt - [13522 bytes] - [25/02/2015 11:47:45]
AdwCleaner[S0].txt - [14511 bytes] - [25/02/2015 12:04:00]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14571 bytes] ##########
-
zdenek72
- 3. Stupeň Varování
- Příspěvky: 106
- Registrován: 09 úno 2010 15:18
- Bydliště: Plzen, Czech Republic
- Kontaktovat uživatele:
Re: Prosím o kontrolu
Zoek.exe v5.0.0.0 Updated 24-February-2015
Tool run by Blanka on st 25.02.2015 at 12:15:38,37.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Blanka\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25.2.2015 12:18:59 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\1acf32df-b1fe-4175-996d-52aaa728b99a deleted successfully
C:\PROGRA~2\b293b0ed-4515-48e8-8fd9-956160943535 deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\PCData deleted successfully
C:\Program Files\ATI Technologies deleted successfully
C:\Program Files\Dell deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\Blanka\AppData\Roaming\DiskDefrag deleted successfully
C:\Users\Hoooonza\AppData\Roaming\Roxio deleted successfully
C:\Users\Blanka\AppData\Local\cache deleted successfully
C:\Users\Blanka\AppData\Local\CrashDumps deleted successfully
C:\Users\Blanka\AppData\Local\CRE deleted successfully
C:\Users\Blanka\AppData\Local\dvrdata deleted successfully
C:\Users\Guest\AppData\Local\VirtualStore deleted successfully
C:\Users\Hoooonza\AppData\Local\{13CD4650-07F9-4ACA-8AEE-569C1B6EA5A0} deleted successfully
C:\Users\Hoooonza\AppData\Local\{16F58C8B-951F-4E17-B3B9-700B1C2558F6} deleted successfully
C:\Users\Hoooonza\AppData\Local\{2B35146C-E624-45FD-93A8-A526527C77E3} deleted successfully
C:\Users\Hoooonza\AppData\Local\{3854F670-95E6-4479-8F9F-82A30C8248EF} deleted successfully
C:\Users\Hoooonza\AppData\Local\{3CC30713-DE10-48F6-8847-F05D97F58B37} deleted successfully
C:\Users\Hoooonza\AppData\Local\{4357E4C1-4F2B-4B7E-BB2D-70688718B650} deleted successfully
C:\Users\Hoooonza\AppData\Local\{4BC3262E-4C92-4034-99B8-94EBDF9E87A5} deleted successfully
C:\Users\Hoooonza\AppData\Local\{52801997-53F9-43C7-B2BF-F27F7B28A71F} deleted successfully
C:\Users\Hoooonza\AppData\Local\{52EB8787-F164-4793-8677-177EA08E5954} deleted successfully
C:\Users\Hoooonza\AppData\Local\{5F74C51D-E439-4714-AE0C-1E4B94B35C3A} deleted successfully
C:\Users\Hoooonza\AppData\Local\{6AC1B607-BBEE-4540-8FFC-FBCF1FB32171} deleted successfully
C:\Users\Hoooonza\AppData\Local\{6BD9B3D3-78BD-4C23-B39E-D52D7B36BC41} deleted successfully
C:\Users\Hoooonza\AppData\Local\{83C7DCAD-E6E9-4923-9DAD-E994A995E71F} deleted successfully
C:\Users\Hoooonza\AppData\Local\{8DFA904A-9904-401C-8178-7C5292B652D5} deleted successfully
C:\Users\Hoooonza\AppData\Local\{93FB038B-A1B7-4E06-A2F2-440BDD74FDFF} deleted successfully
C:\Users\Hoooonza\AppData\Local\{A55218C3-E09A-41C4-B464-0BEFC1D9BCC1} deleted successfully
C:\Users\Hoooonza\AppData\Local\{AA0D0A1D-4432-45B0-AE45-8EF3D65F8935} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B38E6EE0-7C25-4056-9CE8-1D96812CC843} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B56CB4C9-574D-4420-940D-398DE728DA80} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B6C4AF8A-6202-45F5-9D35-E491B9571622} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B811C95B-0231-4648-B036-C15A8299EA6A} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B8A2B38C-1DF9-45C7-8E40-38A4D4B16602} deleted successfully
C:\Users\Hoooonza\AppData\Local\{BE39CA2B-5A5A-476A-ACA3-AD10AA1AA349} deleted successfully
C:\Users\Hoooonza\AppData\Local\{BEC16069-92FA-43B9-92D7-4DF94C40FF58} deleted successfully
C:\Users\Hoooonza\AppData\Local\{CA3DB59A-7F63-4E62-BD30-89012B0BEC29} deleted successfully
C:\Users\Hoooonza\AppData\Local\{D2AF8987-260E-4435-8404-7CED6B5ACB23} deleted successfully
C:\Users\Hoooonza\AppData\Local\{D65FEFB8-0AD0-482D-9F0E-EEAE617043C6} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DC4AFAF8-92FD-42E6-BB9D-947156889420} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DD029711-370E-406F-8C3F-28B4D7E80466} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DFDAC1F9-17D8-4506-9907-F21FBC1294E9} deleted successfully
C:\Users\Hoooonza\AppData\Local\{E69C376D-BA93-440A-BB47-7B5C03EAC0AE} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F363E3E8-C7C1-44FE-B771-AC34B5AD51FD} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F5299567-2588-4D4A-AE5B-08082A2551FC} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F88BF7AB-B56E-4166-9D89-F540126F408D} deleted successfully
C:\Users\Hoooonza\AppData\Local\{FEB03DBE-BA04-46EA-8BBB-3A24BA915FFC} deleted successfully
C:\Users\NightCore\AppData\Local\VirtualStore deleted successfully
C:\Users\NightCore\AppData\Local\{BF7B76A3-486A-4C14-B69B-4809DF2B454E} deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08bc52be-26ef-4e8b-aa1d-71b0e439e7fb} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14FE3F5A-4023-4329-A9B3-B03A75C94219} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1640F3E-1161-42EA-9EB2-918629B5564} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A3D8D4D-665-4A27-ADB0-1AB2F059FB5E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A7B02B8-C46F-49E7-8A3F-115272887D9C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1B1187A5-CC25-401A-862D-D887212CB2EB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1BF1D2CD-D7BC-41F8-96D0-4929B349414C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1C220FD0-E67A-4530-9C80-2991BA15CF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E783E7C-7DE9-42BB-947C-2DFF5C246A0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1EA34FDD-E04C-49FA-9F5D-42BEB4485F2F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2231B4C0-B1DA-48EE-B524-97549C273C1E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{24AE5AEB-65C5-4683-947E-24241681F4D2} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2572348E-D998-47E6-B741-2A1B3E1C93F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29EC2E51-B785-4911-ADDA-A32FFFD863BC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BF4F40B-AAA1-4374-80E-F45F9FF3988} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2C0E50A9-13E6-413C-8FBC-63EF6419C941} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2EF93645-E5D8-46C6-9056-631ACA9EB6AA} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{342C092D-D6E6-4E0E-AA23-6AD79581D7D0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38193187-7C2E-4E23-923D-C98D5D8CBE6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38AE414B-8179-4275-A195-4133E8ECCC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B1DC92A-8635-42CE-A8A6-4325F214D23} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{413943FC-6321-4733-82CC-7F7E88F13877} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4190D4F9-166E-4AB1-BC5D-8580779F5B95} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E3C18B6-ADF3-4073-92C2-BE161AEF54EC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E6C2961-CFA6-4628-A126-E4F99358FC3} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50810BF5-7321-4F83-981A-230ECA6251C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{512C9B5F-114E-4BBB-8A40-3497DC61B08D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51FE7F7A-A2B2-4147-BC49-A2AB6C268A55} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54295496-F132-4F99-A1E6-68122636B81C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{558F3593-EB0B-492A-829F-3F31739F7D39} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{565D6EF-DD5D-4CED-9068-A69D9ABB859} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5987BE34-DEF1-42E5-8BE7-A3AEB513619} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C36053A-6525-4BC0-80DD-35F4EF447C4} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F1BA93C-8435-4BF2-8D6C-FB97235B4ED7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F2045EB-8C7C-43E3-9BB3-FD2E129F1B19} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F99DECB-A4C0-4A26-90CB-86ED27B82C53} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639e6516-6aeb-42aa-9ec4-f95b2470fb63} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{642E145B-AFC5-4FFF-9C90-156D02B8D92} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{646708B6-4605-4873-9770-D6B34BC83F29} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65194982-CFB4-47EC-BF29-1A4B8447B5AC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{690E8FF7-F32F-4CE0-B0C0-10EF869DADC6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69662A8E-6152-41FE-8391-9FD0D98CDC9A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E9329DA-800F-4CF8-8F54-DF6511F372BD} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{706A5B0E-D906-40AF-8764-7A5D37961AF5} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73144B00-1890-422A-84E9-9A689DC93229} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7480DA1C-F401-4745-B521-4F447230DE2D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C525FD-8CD-4D2B-87E0-294BE88F45F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{795C16A4-7ACC-4804-AB74-D1EF43C92989} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7BF69C34-953F-4E9D-81A9-A179F83B4B7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C1A6125-8132-45EE-A9E4-42506331636A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E1B5FB0-558C-4084-83B6-DB4585C71759} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E5EDF40-B2E5-4137-A0BA-EFAAE8DD5D6E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EBB1BE0-A044-4B76-92D1-6029C6B70AC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EE11A6F-A07F-4445-A313-89F7E16648B4} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82827D5F-8CCA-492A-A4FA-752EF186F4D9} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86fb34c3-d209-4175-918e-f108ad242370} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87BC427E-2ED-4BFA-85A9-853BE7841A50} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{891AF2F9-4575-46D5-A61E-BC787428555D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A448986-48BB-4C41-A384-4C9F8BC7C8B8} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8D5B801F-DF2E-45CC-A7BE-8CC6F4927D27} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E18055C-61EB-4DA6-9BD5-B3FE2134755} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90A7D285-CDCE-42A2-A930-C18C4AB7A522} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BA744B0-4C58-4FB7-977C-6654CEE5C238} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BDC0686-E544-4711-AC49-9BC9F0972EF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A41D0CCE-1BD7-4956-9072-2176F646F80} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4CF817-F622-4489-8C95-4E6EFF36B116} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A57BA5B7-C7B4-404C-894E-9D97CE59758} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A66C0F90-172A-45EB-BA34-AD3685B078DE} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A7700861-6373-4909-845B-2F8F5D8265BA} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A83FC9D9-8932-4DC2-9A55-D5EFA8F58E66} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88635D7-F375-4B33-A938-2061BA13C4A1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A91E5495-D14E-4EED-98C5-685AF67D3926} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A98018-E62D-46D8-A763-BB455F4C3048} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAE7DC13-24A7-41E3-817A-385C91C34445} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B09904BB-2E0A-4D29-A7EC-1A2A1E10FF77} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0A50919-92DB-4A6C-BCEF-E59698514B0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1709EF2-1B4E-468A-B77B-FAD1967858AB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2E9D05F-F3B6-4278-B3D-BA48EACC3E1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5337CEA-9ED7-445E-98C8-46A653A44FDB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B55D0EE-A69B-4F04-AFA7-3B621490DBE7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5DF9BEF-4300-4FF2-A1DF-B8ECE051FE6F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC21FF49-AD4A-4A71-96FD-80F0D38DC62C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAAA2794-BFF9-46A4-8BE1-4E1FF610F117} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D18EB3F4-E5DC-43B9-9561-32687A7AF1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5275CCE-C5A5-4088-9AAF-6D823116E61} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d54b5630-8019-4946-a220-cfcc8771100a} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5AB06CE-C84A-4C18-8ED-7E4BC235CDD6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBCE7F65-94F9-4891-8E2B-2A719524B94A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF7863E0-72B5-4785-A54-BFC8665A38C6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFC610F4-D947-4EA9-8C1F-48ED8B020CF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E02F1033-3B46-48EE-8381-8148A4CB40E8} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E886C3FF-FB29-4057-BB3-9C8BFEC6EBE} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E90D2FA4-5F1B-405A-8AA6-DDE33B9626} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E967D0C-13E2-4A02-8599-AFD74F779DE9} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE6C381B-2FC3-445C-A7EE-4AE176AB345F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEAC6199-8DB5-4D33-BDB4-BA1240901BC1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F15F4FFC-F9EE-4A3C-874F-82A447D34EDD} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4ACE370-716F-4C6C-811E-F0A265862E63} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9804FA6-593A-4138-951E-D4746E7EC67B} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE1175B1-901A-4900-893F-4892A73E8036} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08bc52be-26ef-4e8b-aa1d-71b0e439e7fb} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639e6516-6aeb-42aa-9ec4-f95b2470fb63} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86fb34c3-d209-4175-918e-f108ad242370} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d54b5630-8019-4946-a220-cfcc8771100a} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{eeaebaf9-6fa8-41dc-9ff4-3f7d4b159107} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8f57bb18-b93c-4b6c-9910-9de3bfdaa99e} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{ae61fe57-e2a8-4035-a4fb-4e5698453604} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8c558430-aa19-4c4b-acb7-5009a91fd392} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611171152} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Mozilla\Firefox\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668");
user_pref("browser.search.defaulturl", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
user_pref("keyword.URL", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\prefs.js:
Deleted from C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
Added to C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.defaultenginename", "Google (avast)");
user_pref("browser.search.order.1", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\prefs.js:
Deleted from C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.defaultenginename", "Google (avast)");
user_pref("browser.search.selectedEngine", "Google (avast)");
user_pref("browser.search.order.1", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");
Added to C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default
user.js not found
---- Lines {e4f94d1e-2f53-401e-8885-681602c0ddd8} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@MediaViewV1alpha8711.net\":{\"descriptor\":\"C:\\\\Program Fi
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\1acf32df-b1fe-4175-996d-52aaa728b99a not found
C:\PROGRA~2\b293b0ed-4515-48e8-8fd9-956160943535 not found
C:\PROGRA~2\MSXML 4.0 not found
C:\PROGRA~2\PCData not found
C:\Users\Hoooonza\AppData\Local\1705 deleted
C:\Users\Hoooonza\AppData\Local\26330 deleted
C:\Users\Blanka\.android deleted
C:\PROGRA~2\GUT523E.tmp deleted
C:\PROGRA~2\GUM522D.tmp deleted
C:\Users\Hoooonza\AppData\Roaming\MC Titan FTB deleted
C:\PROGRA~3\Package Cache deleted
C:\windows\SysNative\tasks\Microsoft\Windows\Maintenance\SMupdate2 deleted
C:\windows\SysNative\tasks\Microsoft\Windows\Multimedia\SMupdate3 deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\CT3289075 deleted
"C:\Users\Blanka\AppData\Roaming\Mc Titan FTB" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.01.2015 14:34]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Undetermined - wrc@avast.com
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default
- Undetermined - jsonview@brh.numbera.com
- Undetermined - {4bd643ce-8ef9-41bb-9b43-501b4f8fae85}
- jsonviewbrhnumberacom - %ProfilePath%\extensions\jsonview@brh.numbera.com
- Cyti Web 1.0.1 - %ProfilePath%\extensions\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}.xpi
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
- Undetermined - C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\extensions\PDVDZDW52397720@XDDWJXW57740856.com
- Undetermined - C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
77887617FA24E755A5A431E3E28E25E1 - C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll - Shockwave for Director / Shockwave for Director
C62322C77D1AAB77B1CF1130FCC3673A - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
09B4E13D25623D879D35286E2D29FF13 - C:\Users\Blanka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
==== Chromium Look ======================
Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[18.11.2014 21:46]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14.07.2014 18:22]
Avast SafePrice - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Skype Click to Call - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Seznam Lištička - Email - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Media View - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\empchnpknapfpepbbccinpofmaaofgbm
Media Buzz - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnkgjcpmoekepdaabgbnlddiejmkooj
Rich Media View - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkclmlhnfkahfdjcedgcgjalflkhmeaj
Media Watch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfccibknlkgcphdklnhekkdfnjajbmcf
Cyti Web - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\dckoiijbfmmlaaajifhilhncpmdjjogn
efjjgphedlaihnlgaibiaihhmhaejjdd - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjjgphedlaihnlgaibiaihhmhaejjdd
Seznam Lištička - Rychlá volba - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibfgbclmgnmffinenpipoibfdoblond
Seznam Lištička - Email - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkfpcckoflkdgjdobdkpclgngaahgbpi
Seznam LištiÄŤka - SlovnĂk - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghoooididkjbjjldgojdgceoinbhbjmh
Avast Online Security - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Seznam Lištička - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\lelcohngbjgpiibagnfmncojacafbbpg
Seznam Lištička - Email - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Battlefield Heroes - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh
Avast Online Security - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Skype Click to Call - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
==== Chromium Startpages ======================
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/?clid=12454",
==== Chromium Fix ======================
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.omiga-plus.com_0.localstorage deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.omiga-plus.com_0.localstorage-journal deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_omigaplus2.inspsearch.com_0.localstorage deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_omigaplus2.inspsearch.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} Seznam Url="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
==== Reset Google Chrome ======================
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Web Data will be reset at reboot
==== shortcuts on Users Desktops ======================
C:\Users\Blanka\Desktop\CCleaner – zástupce.lnk -
C:\Users\Blanka\Desktop\Domácí skupina – zástupce.lnk -
C:\Users\Blanka\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Blanka\Desktop\Počítač – zástupce.lnk -
C:\Users\Blanka\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Blanka\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Users\Blanka\Desktop\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\Users\Blanka\Desktop\vše\Bandicam.lnk -
C:\Users\Blanka\Desktop\čističe\AdmWin.lnk -
C:\Users\Blanka\Desktop\čističe\Glary Utilities 5.lnk -
C:\Users\Blanka\Desktop\čističe\Opera.lnk -
C:\Users\Blanka\Desktop\čističe\PDFCreator.lnk -
C:\Users\Blanka\Desktop\čističe\SlimDrivers.lnk -
C:\Users\Guest\Desktop\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Guest\Desktop\Origin.lnk - C:\Program Files (x86)\Origin\Origin.exe
C:\Users\Hoooonza\Desktop\Avast Free Antivirus.lnk - C:\Program Files (x86)\AVAST Software\Avast\avastui.exe
C:\Users\Hoooonza\Desktop\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Hoooonza\Desktop\CCleaner – zástupce.lnk -
C:\Users\Hoooonza\Desktop\Fraps.lnk - C:\Fraps\fraps.exe
C:\Users\Hoooonza\Desktop\Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe
C:\Users\Hoooonza\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\Desktop\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Users\Hoooonza\Desktop\Minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe
C:\Users\Hoooonza\Desktop\osu.lnk -
C:\Users\Hoooonza\Desktop\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
C:\Users\Hoooonza\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Hoooonza\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Hoooonza\Desktop\Windows Live Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Hoooonza\Desktop\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Hoooonza\Desktop\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe
C:\Users\Hoooonza\Desktop\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\Users\Hoooonza\Desktop\Čarovný-Minecraft-1.5.2.lnk -
C:\Users\Hoooonza\Desktop\New\.minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft
C:\Users\NightCore\Desktop\Anime.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CC 2014\Photoshop.exe
C:\Users\NightCore\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\NightCore\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\Desktop\osu.lnk -
C:\Users\NightCore\Desktop\photoshop – zástupce.lnk -
C:\Users\NightCore\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\NightCore\Desktop\WeatherBug®.lnk -
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Public\Desktop\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk - C:\Users\Blanka\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps\Fraps.lnk - C:\Fraps\fraps.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps\Uninstall.lnk - C:\Fraps\uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake\Uninstall\Uninstall Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\Uninstall\unins000.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer Setup Wizard.lnk - C:\Program Files (x86)\The KMPlayer\KMPSetup.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer.lnk - C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\Uninstall KMPlayer.lnk - C:\Program Files (x86)\The KMPlayer\uninstall.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\WeatherBug®.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --app=http://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1366,768
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --appletID=HomePanel_BL --appletVersion=1.0
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\windows\Installer\{AC76BA86-7AD7-1029-7B44-AB0000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk - C:\Program Files (x86)\Microsoft Security Client\msseces.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files (x86)\Opera\launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\AdFender.lnk - C:\Program Files (x86)\AdFender\AdFender.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\Help.lnk - C:\Program Files (x86)\AdFender\AdFender.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\Readme.lnk - C:\Program Files (x86)\AdFender\Readme.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\AdmWin.lnk - C:\AdmWin\AdmWin.EXE
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\Nápověda.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\Odinstalovat.lnk - C:\AdmWin\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\HP Scan.lnk - C:\Program Files (x86)\HP\HP Deskjet 2050 J510 series\bin\HPScan.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Nastavení tiskárny a softwaru.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Nápověda.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Odinstalovat.lnk - C:\Windows\SysWOW64\msiexec.exe /qb /x {F61FD928-A74D-4AF9-9667-BE2BB6F2C386}
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Webová stránka podpory produktu.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Zakoupit spotřební materiál.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab about
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\Uninstall.lnk - C:\windows\SysWOW64\msiexec.exe /i {9880E2B8-2B8F-4B77-92C9-02DF213C6B93} REMOVE=ALL
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Odinstalovat aplikaci Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan\Norton Security Scan.LNK - C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan\Uninstall Norton Security Scan.LNK - C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\InstWrap.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk - C:\Program Files (x86)\Notepad++\notepad++.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers\SlimDrivers Help.lnk - C:\windows\Installer\{A5457401-D56A-43F2-9524-78E54A7FC07A}\Icon.exe -help
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers\SlimDrivers.lnk - C:\windows\Installer\{A5457401-D56A-43F2-9524-78E54A7FC07A}\Icon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AdFender.lnk - C:\Program Files (x86)\AdFender\AdFender.exe -autostart
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\Uninstall WeatherBug®.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\WeatherBug® Update.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\WeatherBug®.lnk -
==== shortcuts in Quick Launch ======================
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --remote-debugging-port=9223
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk - C:\Program Files (x86)\Xfire\Xfire.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --profile-directory="Profile 1"
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk - C:\windows\system32\mspaint.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Snipping Tool.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk - C:\windows\system32\calc.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup (2).lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup (3).lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup .lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Poznámkový blok.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\70f62c6a7f1739bd\pinned.lnk - C:\windows\system32\rundll32.exe C:\windows\system32\shell32.dll,Options_RunDLL 1
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk - C:\windows\system32\mspaint.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner – zástupce.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\osu.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Live Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --app=http://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1366,768
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Avast Free Antivirus.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
==== shortcuts After Repair ======================
C:\Users\Hoooonza\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe -extoff
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickSet deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Blanka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache will be emptied at reboot
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=3285 folders=434 487850806 bytes)
==== Empty Temp Folders ======================
C:\Users\Blanka\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\Hoooonza\AppData\Local\Temp emptied successfully
C:\Users\NightCore\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Blanka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Web Data" not found
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_0" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_1" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_2" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_3" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\index" deleted
==== EOF on st 25.02.2015 at 13:21:00,04 ======================
Tool run by Blanka on st 25.02.2015 at 12:15:38,37.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Blanka\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25.2.2015 12:18:59 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\1acf32df-b1fe-4175-996d-52aaa728b99a deleted successfully
C:\PROGRA~2\b293b0ed-4515-48e8-8fd9-956160943535 deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\PCData deleted successfully
C:\Program Files\ATI Technologies deleted successfully
C:\Program Files\Dell deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\Blanka\AppData\Roaming\DiskDefrag deleted successfully
C:\Users\Hoooonza\AppData\Roaming\Roxio deleted successfully
C:\Users\Blanka\AppData\Local\cache deleted successfully
C:\Users\Blanka\AppData\Local\CrashDumps deleted successfully
C:\Users\Blanka\AppData\Local\CRE deleted successfully
C:\Users\Blanka\AppData\Local\dvrdata deleted successfully
C:\Users\Guest\AppData\Local\VirtualStore deleted successfully
C:\Users\Hoooonza\AppData\Local\{13CD4650-07F9-4ACA-8AEE-569C1B6EA5A0} deleted successfully
C:\Users\Hoooonza\AppData\Local\{16F58C8B-951F-4E17-B3B9-700B1C2558F6} deleted successfully
C:\Users\Hoooonza\AppData\Local\{2B35146C-E624-45FD-93A8-A526527C77E3} deleted successfully
C:\Users\Hoooonza\AppData\Local\{3854F670-95E6-4479-8F9F-82A30C8248EF} deleted successfully
C:\Users\Hoooonza\AppData\Local\{3CC30713-DE10-48F6-8847-F05D97F58B37} deleted successfully
C:\Users\Hoooonza\AppData\Local\{4357E4C1-4F2B-4B7E-BB2D-70688718B650} deleted successfully
C:\Users\Hoooonza\AppData\Local\{4BC3262E-4C92-4034-99B8-94EBDF9E87A5} deleted successfully
C:\Users\Hoooonza\AppData\Local\{52801997-53F9-43C7-B2BF-F27F7B28A71F} deleted successfully
C:\Users\Hoooonza\AppData\Local\{52EB8787-F164-4793-8677-177EA08E5954} deleted successfully
C:\Users\Hoooonza\AppData\Local\{5F74C51D-E439-4714-AE0C-1E4B94B35C3A} deleted successfully
C:\Users\Hoooonza\AppData\Local\{6AC1B607-BBEE-4540-8FFC-FBCF1FB32171} deleted successfully
C:\Users\Hoooonza\AppData\Local\{6BD9B3D3-78BD-4C23-B39E-D52D7B36BC41} deleted successfully
C:\Users\Hoooonza\AppData\Local\{83C7DCAD-E6E9-4923-9DAD-E994A995E71F} deleted successfully
C:\Users\Hoooonza\AppData\Local\{8DFA904A-9904-401C-8178-7C5292B652D5} deleted successfully
C:\Users\Hoooonza\AppData\Local\{93FB038B-A1B7-4E06-A2F2-440BDD74FDFF} deleted successfully
C:\Users\Hoooonza\AppData\Local\{A55218C3-E09A-41C4-B464-0BEFC1D9BCC1} deleted successfully
C:\Users\Hoooonza\AppData\Local\{AA0D0A1D-4432-45B0-AE45-8EF3D65F8935} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B38E6EE0-7C25-4056-9CE8-1D96812CC843} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B56CB4C9-574D-4420-940D-398DE728DA80} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B6C4AF8A-6202-45F5-9D35-E491B9571622} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B811C95B-0231-4648-B036-C15A8299EA6A} deleted successfully
C:\Users\Hoooonza\AppData\Local\{B8A2B38C-1DF9-45C7-8E40-38A4D4B16602} deleted successfully
C:\Users\Hoooonza\AppData\Local\{BE39CA2B-5A5A-476A-ACA3-AD10AA1AA349} deleted successfully
C:\Users\Hoooonza\AppData\Local\{BEC16069-92FA-43B9-92D7-4DF94C40FF58} deleted successfully
C:\Users\Hoooonza\AppData\Local\{CA3DB59A-7F63-4E62-BD30-89012B0BEC29} deleted successfully
C:\Users\Hoooonza\AppData\Local\{D2AF8987-260E-4435-8404-7CED6B5ACB23} deleted successfully
C:\Users\Hoooonza\AppData\Local\{D65FEFB8-0AD0-482D-9F0E-EEAE617043C6} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DC4AFAF8-92FD-42E6-BB9D-947156889420} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DD029711-370E-406F-8C3F-28B4D7E80466} deleted successfully
C:\Users\Hoooonza\AppData\Local\{DFDAC1F9-17D8-4506-9907-F21FBC1294E9} deleted successfully
C:\Users\Hoooonza\AppData\Local\{E69C376D-BA93-440A-BB47-7B5C03EAC0AE} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F363E3E8-C7C1-44FE-B771-AC34B5AD51FD} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F5299567-2588-4D4A-AE5B-08082A2551FC} deleted successfully
C:\Users\Hoooonza\AppData\Local\{F88BF7AB-B56E-4166-9D89-F540126F408D} deleted successfully
C:\Users\Hoooonza\AppData\Local\{FEB03DBE-BA04-46EA-8BBB-3A24BA915FFC} deleted successfully
C:\Users\NightCore\AppData\Local\VirtualStore deleted successfully
C:\Users\NightCore\AppData\Local\{BF7B76A3-486A-4C14-B69B-4809DF2B454E} deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08bc52be-26ef-4e8b-aa1d-71b0e439e7fb} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14FE3F5A-4023-4329-A9B3-B03A75C94219} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1640F3E-1161-42EA-9EB2-918629B5564} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A3D8D4D-665-4A27-ADB0-1AB2F059FB5E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A7B02B8-C46F-49E7-8A3F-115272887D9C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1B1187A5-CC25-401A-862D-D887212CB2EB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1BF1D2CD-D7BC-41F8-96D0-4929B349414C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1C220FD0-E67A-4530-9C80-2991BA15CF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E783E7C-7DE9-42BB-947C-2DFF5C246A0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1EA34FDD-E04C-49FA-9F5D-42BEB4485F2F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2231B4C0-B1DA-48EE-B524-97549C273C1E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{24AE5AEB-65C5-4683-947E-24241681F4D2} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2572348E-D998-47E6-B741-2A1B3E1C93F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29EC2E51-B785-4911-ADDA-A32FFFD863BC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BF4F40B-AAA1-4374-80E-F45F9FF3988} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2C0E50A9-13E6-413C-8FBC-63EF6419C941} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2EF93645-E5D8-46C6-9056-631ACA9EB6AA} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{342C092D-D6E6-4E0E-AA23-6AD79581D7D0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38193187-7C2E-4E23-923D-C98D5D8CBE6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{38AE414B-8179-4275-A195-4133E8ECCC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B1DC92A-8635-42CE-A8A6-4325F214D23} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{413943FC-6321-4733-82CC-7F7E88F13877} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4190D4F9-166E-4AB1-BC5D-8580779F5B95} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E3C18B6-ADF3-4073-92C2-BE161AEF54EC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4E6C2961-CFA6-4628-A126-E4F99358FC3} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50810BF5-7321-4F83-981A-230ECA6251C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{512C9B5F-114E-4BBB-8A40-3497DC61B08D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51FE7F7A-A2B2-4147-BC49-A2AB6C268A55} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54295496-F132-4F99-A1E6-68122636B81C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{558F3593-EB0B-492A-829F-3F31739F7D39} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{565D6EF-DD5D-4CED-9068-A69D9ABB859} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5987BE34-DEF1-42E5-8BE7-A3AEB513619} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C36053A-6525-4BC0-80DD-35F4EF447C4} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F1BA93C-8435-4BF2-8D6C-FB97235B4ED7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F2045EB-8C7C-43E3-9BB3-FD2E129F1B19} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5F99DECB-A4C0-4A26-90CB-86ED27B82C53} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639e6516-6aeb-42aa-9ec4-f95b2470fb63} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{642E145B-AFC5-4FFF-9C90-156D02B8D92} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{646708B6-4605-4873-9770-D6B34BC83F29} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65194982-CFB4-47EC-BF29-1A4B8447B5AC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{690E8FF7-F32F-4CE0-B0C0-10EF869DADC6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69662A8E-6152-41FE-8391-9FD0D98CDC9A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E9329DA-800F-4CF8-8F54-DF6511F372BD} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{706A5B0E-D906-40AF-8764-7A5D37961AF5} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{73144B00-1890-422A-84E9-9A689DC93229} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7480DA1C-F401-4745-B521-4F447230DE2D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{74C525FD-8CD-4D2B-87E0-294BE88F45F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{795C16A4-7ACC-4804-AB74-D1EF43C92989} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7BF69C34-953F-4E9D-81A9-A179F83B4B7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C1A6125-8132-45EE-A9E4-42506331636A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E1B5FB0-558C-4084-83B6-DB4585C71759} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E5EDF40-B2E5-4137-A0BA-EFAAE8DD5D6E} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EBB1BE0-A044-4B76-92D1-6029C6B70AC} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7EE11A6F-A07F-4445-A313-89F7E16648B4} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82827D5F-8CCA-492A-A4FA-752EF186F4D9} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86fb34c3-d209-4175-918e-f108ad242370} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{87BC427E-2ED-4BFA-85A9-853BE7841A50} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{891AF2F9-4575-46D5-A61E-BC787428555D} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A448986-48BB-4C41-A384-4C9F8BC7C8B8} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8D5B801F-DF2E-45CC-A7BE-8CC6F4927D27} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E18055C-61EB-4DA6-9BD5-B3FE2134755} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90A7D285-CDCE-42A2-A930-C18C4AB7A522} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BA744B0-4C58-4FB7-977C-6654CEE5C238} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9BDC0686-E544-4711-AC49-9BC9F0972EF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A41D0CCE-1BD7-4956-9072-2176F646F80} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4CF817-F622-4489-8C95-4E6EFF36B116} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A57BA5B7-C7B4-404C-894E-9D97CE59758} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A66C0F90-172A-45EB-BA34-AD3685B078DE} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A7700861-6373-4909-845B-2F8F5D8265BA} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A83FC9D9-8932-4DC2-9A55-D5EFA8F58E66} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88635D7-F375-4B33-A938-2061BA13C4A1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A91E5495-D14E-4EED-98C5-685AF67D3926} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A98018-E62D-46D8-A763-BB455F4C3048} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AAE7DC13-24A7-41E3-817A-385C91C34445} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B09904BB-2E0A-4D29-A7EC-1A2A1E10FF77} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0A50919-92DB-4A6C-BCEF-E59698514B0} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B1709EF2-1B4E-468A-B77B-FAD1967858AB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2E9D05F-F3B6-4278-B3D-BA48EACC3E1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5337CEA-9ED7-445E-98C8-46A653A44FDB} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B55D0EE-A69B-4F04-AFA7-3B621490DBE7} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B5DF9BEF-4300-4FF2-A1DF-B8ECE051FE6F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC21FF49-AD4A-4A71-96FD-80F0D38DC62C} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAAA2794-BFF9-46A4-8BE1-4E1FF610F117} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D18EB3F4-E5DC-43B9-9561-32687A7AF1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5275CCE-C5A5-4088-9AAF-6D823116E61} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d54b5630-8019-4946-a220-cfcc8771100a} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5AB06CE-C84A-4C18-8ED-7E4BC235CDD6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DBCE7F65-94F9-4891-8E2B-2A719524B94A} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DF7863E0-72B5-4785-A54-BFC8665A38C6} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFC610F4-D947-4EA9-8C1F-48ED8B020CF} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E02F1033-3B46-48EE-8381-8148A4CB40E8} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E886C3FF-FB29-4057-BB3-9C8BFEC6EBE} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E90D2FA4-5F1B-405A-8AA6-DDE33B9626} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E967D0C-13E2-4A02-8599-AFD74F779DE9} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE6C381B-2FC3-445C-A7EE-4AE176AB345F} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEAC6199-8DB5-4D33-BDB4-BA1240901BC1} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F15F4FFC-F9EE-4A3C-874F-82A447D34EDD} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4ACE370-716F-4C6C-811E-F0A265862E63} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9804FA6-593A-4138-951E-D4746E7EC67B} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE1175B1-901A-4900-893F-4892A73E8036} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{08bc52be-26ef-4e8b-aa1d-71b0e439e7fb} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{639e6516-6aeb-42aa-9ec4-f95b2470fb63} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{86fb34c3-d209-4175-918e-f108ad242370} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d54b5630-8019-4946-a220-cfcc8771100a} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{eeaebaf9-6fa8-41dc-9ff4-3f7d4b159107} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8f57bb18-b93c-4b6c-9910-9de3bfdaa99e} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{ae61fe57-e2a8-4035-a4fb-4e5698453604} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8c558430-aa19-4c4b-acb7-5009a91fd392} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611171152} deleted successfully
HKEY_USERS\S-1-5-21-412466861-1309505891-1087973670-1000\Software\Mozilla\Firefox\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/?clid=22668");
user_pref("browser.search.defaulturl", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
user_pref("keyword.URL", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\prefs.js:
Deleted from C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
Added to C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.defaultenginename", "Google (avast)");
user_pref("browser.search.order.1", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default\prefs.js:
Deleted from C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/?trackid=sp-006");
user_pref("browser.search.defaulturl", "https://www.google.com/search/?trackid=sp-006");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.defaultengine", "Google (avast)");
user_pref("browser.search.defaultenginename", "Google (avast)");
user_pref("browser.search.selectedEngine", "Google (avast)");
user_pref("browser.search.order.1", "Google (avast)");
user_pref("keyword.URL", "https://www.google.com/search/?trackid=sp-006");
Added to C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default
user.js not found
---- Lines {e4f94d1e-2f53-401e-8885-681602c0ddd8} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@MediaViewV1alpha8711.net\":{\"descriptor\":\"C:\\\\Program Fi
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_25.02.2015_1255_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\1acf32df-b1fe-4175-996d-52aaa728b99a not found
C:\PROGRA~2\b293b0ed-4515-48e8-8fd9-956160943535 not found
C:\PROGRA~2\MSXML 4.0 not found
C:\PROGRA~2\PCData not found
C:\Users\Hoooonza\AppData\Local\1705 deleted
C:\Users\Hoooonza\AppData\Local\26330 deleted
C:\Users\Blanka\.android deleted
C:\PROGRA~2\GUT523E.tmp deleted
C:\PROGRA~2\GUM522D.tmp deleted
C:\Users\Hoooonza\AppData\Roaming\MC Titan FTB deleted
C:\PROGRA~3\Package Cache deleted
C:\windows\SysNative\tasks\Microsoft\Windows\Maintenance\SMupdate2 deleted
C:\windows\SysNative\tasks\Microsoft\Windows\Multimedia\SMupdate3 deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default\CT3289075 deleted
"C:\Users\Blanka\AppData\Roaming\Mc Titan FTB" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\cp50ihr9.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [27.01.2015 14:34]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Undetermined - wrc@avast.com
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
ProfilePath: C:\Users\Hoooonza\AppData\Roaming\Mozilla\Firefox\Profiles\pi030hzt.default
- Undetermined - jsonview@brh.numbera.com
- Undetermined - {4bd643ce-8ef9-41bb-9b43-501b4f8fae85}
- jsonviewbrhnumberacom - %ProfilePath%\extensions\jsonview@brh.numbera.com
- Cyti Web 1.0.1 - %ProfilePath%\extensions\{4bd643ce-8ef9-41bb-9b43-501b4f8fae85}.xpi
ProfilePath: C:\Users\NIGHTC~1\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default
- Undetermined - C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\extensions\PDVDZDW52397720@XDDWJXW57740856.com
- Undetermined - C:\Users\NightCore\AppData\Roaming\Mozilla\Firefox\Profiles\yyw4g7hm.default\extensions\e9d197d59f2f45f382b1aa5c14d82@8706aaed9b904554b5cb7984e9.com
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Blanka\AppData\Roaming\Mozilla\Firefox\Profiles\z43atfmt.default
77887617FA24E755A5A431E3E28E25E1 - C:\windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll - Shockwave for Director / Shockwave for Director
C62322C77D1AAB77B1CF1130FCC3673A - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll - Shockwave Flash
09B4E13D25623D879D35286E2D29FF13 - C:\Users\Blanka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
==== Chromium Look ======================
Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[18.11.2014 21:46]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14.07.2014 18:22]
Avast SafePrice - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki
Skype Click to Call - Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Seznam Lištička - Email - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Media View - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\empchnpknapfpepbbccinpofmaaofgbm
Media Buzz - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnkgjcpmoekepdaabgbnlddiejmkooj
Rich Media View - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkclmlhnfkahfdjcedgcgjalflkhmeaj
Media Watch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfccibknlkgcphdklnhekkdfnjajbmcf
Cyti Web - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\dckoiijbfmmlaaajifhilhncpmdjjogn
efjjgphedlaihnlgaibiaihhmhaejjdd - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjjgphedlaihnlgaibiaihhmhaejjdd
Seznam Lištička - Rychlá volba - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibfgbclmgnmffinenpipoibfdoblond
Seznam Lištička - Email - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkfpcckoflkdgjdobdkpclgngaahgbpi
Seznam LištiÄŤka - SlovnĂk - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghoooididkjbjjldgojdgceoinbhbjmh
Avast Online Security - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Seznam Lištička - Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Extensions\lelcohngbjgpiibagnfmncojacafbbpg
Seznam Lištička - Email - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Battlefield Heroes - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh
Avast Online Security - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Skype Click to Call - NightCore\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
==== Chromium Startpages ======================
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/?clid=12454",
==== Chromium Fix ======================
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.omiga-plus.com_0.localstorage deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.omiga-plus.com_0.localstorage-journal deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_omigaplus2.inspsearch.com_0.localstorage deleted successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_omigaplus2.inspsearch.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} Seznam Url="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
==== Reset Google Chrome ======================
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Web Data will be reset at reboot
==== shortcuts on Users Desktops ======================
C:\Users\Blanka\Desktop\CCleaner – zástupce.lnk -
C:\Users\Blanka\Desktop\Domácí skupina – zástupce.lnk -
C:\Users\Blanka\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Blanka\Desktop\Počítač – zástupce.lnk -
C:\Users\Blanka\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Blanka\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Users\Blanka\Desktop\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\Users\Blanka\Desktop\vše\Bandicam.lnk -
C:\Users\Blanka\Desktop\čističe\AdmWin.lnk -
C:\Users\Blanka\Desktop\čističe\Glary Utilities 5.lnk -
C:\Users\Blanka\Desktop\čističe\Opera.lnk -
C:\Users\Blanka\Desktop\čističe\PDFCreator.lnk -
C:\Users\Blanka\Desktop\čističe\SlimDrivers.lnk -
C:\Users\Guest\Desktop\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Guest\Desktop\Origin.lnk - C:\Program Files (x86)\Origin\Origin.exe
C:\Users\Hoooonza\Desktop\Avast Free Antivirus.lnk - C:\Program Files (x86)\AVAST Software\Avast\avastui.exe
C:\Users\Hoooonza\Desktop\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Hoooonza\Desktop\CCleaner – zástupce.lnk -
C:\Users\Hoooonza\Desktop\Fraps.lnk - C:\Fraps\fraps.exe
C:\Users\Hoooonza\Desktop\Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\FreemakeVideoConverter.exe
C:\Users\Hoooonza\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\Desktop\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Users\Hoooonza\Desktop\Minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe
C:\Users\Hoooonza\Desktop\osu.lnk -
C:\Users\Hoooonza\Desktop\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
C:\Users\Hoooonza\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Hoooonza\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Hoooonza\Desktop\Windows Live Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Hoooonza\Desktop\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Hoooonza\Desktop\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe
C:\Users\Hoooonza\Desktop\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\Users\Hoooonza\Desktop\Čarovný-Minecraft-1.5.2.lnk -
C:\Users\Hoooonza\Desktop\New\.minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft
C:\Users\NightCore\Desktop\Anime.lnk - C:\Program Files (x86)\Adobe\Adobe Photoshop CC 2014\Photoshop.exe
C:\Users\NightCore\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\NightCore\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\Desktop\osu.lnk -
C:\Users\NightCore\Desktop\photoshop – zástupce.lnk -
C:\Users\NightCore\Desktop\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\NightCore\Desktop\WeatherBug®.lnk -
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Public\Desktop\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Blanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk - C:\Users\Blanka\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps\Fraps.lnk - C:\Fraps\fraps.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps\Uninstall.lnk - C:\Fraps\uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake\Uninstall\Uninstall Freemake Video Converter.lnk - C:\Program Files (x86)\Freemake\Freemake Video Converter\Uninstall\unins000.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Minecraft.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Minecraft Launcher.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft\Uninstall.lnk - C:\Users\Hoooonza\AppData\Roaming\.minecraft\minecraft launcher\Uninstall.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 2050 J510 series.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer Setup Wizard.lnk - C:\Program Files (x86)\The KMPlayer\KMPSetup.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\KMPlayer.lnk - C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer\Uninstall KMPlayer.lnk - C:\Program Files (x86)\The KMPlayer\uninstall.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\WeatherBug®.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff
C:\Users\NightCore\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Imperia Online\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --app=http://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1366,768
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --appletID=HomePanel_BL --appletVersion=1.0
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\windows\Installer\{AC76BA86-7AD7-1029-7B44-AB0000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk - C:\Program Files (x86)\Microsoft Security Client\msseces.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files (x86)\Opera\launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk - C:\Program Files (x86)\paint.net\PaintDotNet.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\AdFender.lnk - C:\Program Files (x86)\AdFender\AdFender.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\Help.lnk - C:\Program Files (x86)\AdFender\AdFender.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdFender\Readme.lnk - C:\Program Files (x86)\AdFender\Readme.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\AdmWin.lnk - C:\AdmWin\AdmWin.EXE
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\Nápověda.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AdmWin\Odinstalovat.lnk - C:\AdmWin\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\HP Scan.lnk - C:\Program Files (x86)\HP\HP Deskjet 2050 J510 series\bin\HPScan.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Nastavení tiskárny a softwaru.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Nápověda.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Odinstalovat.lnk - C:\Windows\SysWOW64\msiexec.exe /qb /x {F61FD928-A74D-4AF9-9667-BE2BB6F2C386}
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Webová stránka podpory produktu.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Deskjet 2050 J510 series\Zakoupit spotřební materiál.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab about
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\Uninstall.lnk - C:\windows\SysWOW64\msiexec.exe /i {9880E2B8-2B8F-4B77-92C9-02DF213C6B93} REMOVE=ALL
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Odinstalovat aplikaci Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan\Norton Security Scan.LNK - C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan\Uninstall Norton Security Scan.LNK - C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\InstWrap.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk - C:\Program Files (x86)\Notepad++\notepad++.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers\SlimDrivers Help.lnk - C:\windows\Installer\{A5457401-D56A-43F2-9524-78E54A7FC07A}\Icon.exe -help
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers\SlimDrivers.lnk - C:\windows\Installer\{A5457401-D56A-43F2-9524-78E54A7FC07A}\Icon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AdFender.lnk - C:\Program Files (x86)\AdFender\AdFender.exe -autostart
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk - C:\Program Files (x86)\VideoLAN\VLC\Documentation.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk - C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk - C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --reset-config --reset-plugins-cache vlc://quit
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe -Iskins
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\Uninstall WeatherBug®.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\WeatherBug® Update.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WeatherBug®\WeatherBug®.lnk -
==== shortcuts in Quick Launch ======================
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --remote-debugging-port=9223
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Xfire.lnk - C:\Program Files (x86)\Xfire\Xfire.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --profile-directory="Profile 1"
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk - C:\windows\system32\mspaint.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Snipping Tool.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Calculator.lnk - C:\windows\system32\calc.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup (2).lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup (3).lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Counter-Strike 1.6 Setup .lnk - C:\Users\Guest\Saved Games\Microsoft Games\Moje nej hry ;D\Nová složka (3)\cs16full_v42h_cskocz.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Poznámkový blok.lnk -
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Bandicam.lnk - C:\Program Files (x86)\Bandicam\bdcam.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc& ... XX6WS11HLD
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\70f62c6a7f1739bd\pinned.lnk - C:\windows\system32\rundll32.exe C:\windows\system32\shell32.dll,Options_RunDLL 1
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Paint.lnk - C:\windows\system32\mspaint.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CCleaner – zástupce.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\osu.lnk -
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Live Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Imperia Online.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --app=http://www.imperiaonline.org/?ref_ad=src123 --app-window-size=1366,768
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\windows\system32\control.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Avast Free Antivirus.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\NightCore\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
==== shortcuts After Repair ======================
C:\Users\Hoooonza\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe -extoff
C:\Users\Blanka\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Hoooonza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickSet deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Blanka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache will be emptied at reboot
C:\Users\Blanka\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Hoooonza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\NightCore\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=3285 folders=434 487850806 bytes)
==== Empty Temp Folders ======================
C:\Users\Blanka\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\Hoooonza\AppData\Local\Temp emptied successfully
C:\Users\NightCore\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Blanka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Blanka\AppData\Roaming\Opera Software\Opera Stable\Web Data" not found
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_0" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_1" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_2" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\data_3" deleted
"C:\Users\Blanka\AppData\Local\Opera Software\Opera Stable\Cache\index" deleted
==== EOF on st 25.02.2015 at 13:21:00,04 ======================
Re: Prosím o kontrolu
Poprosim o novy log z FRST


Přispějete na provoz fóra?