Zoek.exe v5.0.0.0 Updated 20-Januari-2014
Tool run by Pepino on st 22.01.2014 at 9:34:01,54.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Pepino\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
22.1.2014 9:35:31 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Running Processes ======================
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\atiesrxx.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
D:\Místní disk\Výročí2000\Vyroci.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\PopTray\PopTray.exe
C:\Users\Pepino\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Pepino\Desktop\zoek.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default\prefs.js:
user_pref("backup.old.browser.startup.homepage", "
http://www.google.cz/");
user_pref("browser.startup.homepage", "
http://www.google.com/firefox");
user_pref("browser.search.defaulturl", "");
user_pref("browser.newtab.url", "
http://www.google.com/firefox");
user_pref("browser.search.defaultengine", "Google");
user_pref("backup.old.browser.search.selectedEngine", "");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default\prefs.js:
user_pref("browser.startup.homepage", "
http://www.google.com");
user_pref("browser.search.defaulturl", "
http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "
http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "
http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default
user.js not found
---- Lines defaulttab removed from prefs.js ----
user_pref("extensions.defaulttab.active.affiliate", 4001);
user_pref("extensions.defaulttab.active.overridechromesearch", false);
user_pref("extensions.defaulttab.active.overridekeywordsearch", false);
user_pref("extensions.defaulttab.browserID", "360980630180AD531C208711430AF621");
user_pref("extensions.defaulttab.firstrun", false);
user_pref("extensions.defaulttab.installedVersion", "1.4.2");
---- FireFox user.js and prefs.js backups ----
prefs_22.01.2014_0944_.backup
==== Deleting Files \ Folders ======================
C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357} deleted
C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1} deleted
C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted
C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A} deleted
C:\Users\Pepino\.android deleted
C:\Program Files\File Type Assistant deleted
C:\Program Files\Common Files\Spigot deleted
C:\AUTORUN.INF deleted
C:\Users\Pepino\AppData\Roaming\Uniblue deleted
C:\Users\Pepino\AppData\Roaming\AutoGK.ini deleted
C:\Users\Pepino\AppData\Roaming\Sammsoft deleted
C:\ProgramData\Package Cache deleted
C:\Users\Pepino\AppData\Local\CRE deleted
C:\Users\Pepino\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847} deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\wininit.ini deleted
C:\Windows\system32\tasks\SuperEasyDriverUpdater_UPDATES deleted
C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default\searchplugins\ashampoo-us-customized-web-search.xml deleted
"C:\Users\Pepino\AppData\Local\{87011641-AD7B-4717-936B-5D656D1661B8}" deleted
"C:\Users\Pepino\AppData\Roaming\docInfo" deleted
"C:\Users\Pepino\AppData\Roaming\User Pictures" deleted
"C:\Users\Pepino\AppData\Roaming\Utilities" deleted
"C:\Users\Pepino\AppData\Roaming\Vocal Transformer" deleted
"C:\ProgramData\WebServer" deleted
"C:\ProgramData\Widgets" deleted
"C:\ProgramData\Woodwind" deleted
"C:\Users\Pepino\AppData\Roaming\Vso" deleted
"C:\Users\Pepino\AppData\Roaming\Temp" deleted
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2014-01-13 10:55:18 F042EE4C8D66248D9B86DCF52ABAE416 256000 ----a-w- C:\Windows\PEV.exe
2014-01-13 10:55:18 9E05A9C264C8A908A8E79450FCBFF047 80412 ----a-w- C:\Windows\grep.exe
2014-01-13 10:55:18 5E832F4FAF5F481F2EAF3B3A48F603B8 68096 ----a-w- C:\Windows\zip.exe
2014-01-13 10:55:18 0297C72529807322B152F517FDB0A9FC 406528 ----a-w- C:\Windows\SWSC.exe
2014-01-13 10:55:18 0277C027A26428DB64EF4F64F52BB4FD 208896 ----a-w- C:\Windows\MBR.exe
====== C:\Users\Pepino\AppData\Local\Temp ====
====== Java Cache =====
====== C:\Windows\system32 =====
2014-01-15 10:26:07 1E882889A4314D6DF5DED4F6EC994E72 2349056 ----a-w- C:\Windows\System32\win32k.sys
====== C:\Windows\system32\drivers =====
2014-01-18 18:59:49 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-01-15 10:26:06 EDF2DF71C4F1E13A6AC75F5224DE655A 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2014-01-15 10:26:06 EC2C5AF37B76D7B58C642CB74423DB7A 284672 ----a-w- C:\Windows\System32\drivers\usbport.sys
2014-01-15 10:26:06 D40855F89B69305140BBD7E9A3BA2DA6 43520 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2014-01-15 10:26:06 9828C8D14CC2676421778F0DE638CF97 20480 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2014-01-15 10:26:06 800AABFD625EEFF899F7E5496BDE37AB 24064 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2014-01-15 10:26:06 5DBD4F73E2A52FEED61DBAB3752E329C 240576 ----a-w- C:\Windows\System32\drivers\netio.sys
2014-01-15 10:26:06 0803FBA9FE829D61AE26EC0BCC910C46 76288 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2014-01-15 10:26:05 74F805AB12EB0E3E49E469F19FF02640 6016 ----a-w- C:\Windows\System32\drivers\usbd.sys
2014-01-11 17:04:47 ADD2192FC4DB8E6EFE41B26E0D24BC5B 10844 --sha-w- C:\Windows\System32\drivers\fidbox.idx
2014-01-11 17:04:47 75C29480C5F5A1FBF658A51A3E079533 833568 --sha-w- C:\Windows\System32\drivers\fidbox.dat
2013-12-29 16:39:31 37A6A39C1792BA961EE6172A0F3CA236 64168 ----a-w- C:\Windows\System32\drivers\aswstm.sys
====== C:\Windows\Tasks ======
2014-01-17 19:51:40 -------- d-----w- C:\Windows\system32\Tasks\Safer-Networking
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-01-12 16:09:18 -------- d-----w- C:\Program Files\Trend Micro
2014-01-08 19:53:15 -------- d-----w- C:\Program Files\Calibre2
======= C: =====
2014-01-20 17:30:31 155D005A13A80EE56CD6F0220B9D6E68 512 ----a-w- C:\PhysicalMBR.bin
====== C:\Users\Pepino\AppData\Roaming ======
2014-01-18 11:50:04 30D99D6A7FF94FD74CB4C77BB6DF571A 332851 ----a-w- C:\Users\Pepino\AppData\Local\census.cache
2014-01-18 11:49:36 214A96B65C737E668B2BA0750D083D40 206923 ----a-w- C:\Users\Pepino\AppData\Local\ars.cache
2014-01-17 20:05:40 B7FA7AC35CE43E9E39B9239047563133 36 ----a-w- C:\Users\Pepino\AppData\Local\housecall.guid.cache
2014-01-12 09:42:42 -------- d-----w- C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
2014-01-11 01:50:38 -------- d-----w- C:\Windows\system32\config\systemprofile\AppData\Roaming\Fighters
2014-01-08 19:54:25 -------- d-----w- C:\Users\Pepino\AppData\Local\calibre-cache
2014-01-08 19:53:40 -------- d-----w- C:\Users\Pepino\AppData\Roaming\calibre
====== C:\Users\Pepino ======
2014-01-20 17:26:11 4ADCFEE16EE9978F06157634669D36FB 602112 ----a-w- C:\Users\Pepino\Desktop\OTL.exe
2014-01-15 09:54:40 A3094EA13C935427CD210F6F9AAEE6E9 1220608 ----a-w- C:\Users\Pepino\Desktop\FRST.exe
2014-01-11 17:13:48 -------- d-----w- C:\ProgramData\Preventon
2014-01-11 01:50:41 -------- d-----w- C:\ProgramData\clp
2014-01-08 19:53:15 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
====== C: exe-files ==
2014-01-22 08:22:18 00C2D68C98FA311C1A80EE33ED846923 36500648 ----a-w- C:\Users\Pepino\AppData\Local\Google\Update\Install\{1C2B0D10-38BE-457F-B0DD-F8ECF179545A}\32.0.1700.76_chrome_installer.exe
2014-01-21 15:44:59 FC52ACA5D8F30245CF327C835132F067 10822800 ----a-w- C:\Nikon nový\F-D3200-V103W.exe
2014-01-21 15:29:48 FC52ACA5D8F30245CF327C835132F067 10822800 ----a-w- C:\Stahování\F-D3200-V103W.exe
2014-01-20 17:26:11 4ADCFEE16EE9978F06157634669D36FB 602112 ----a-w- C:\Users\Pepino\Desktop\OTL.exe
2014-01-20 17:24:55 4ADCFEE16EE9978F06157634669D36FB 602112 ----a-w- C:\Stahování\OTL.exe
2014-01-20 13:02:44 49A9D9B4D1C9679A1807529CD3E8E6C0 12160392 ----a-w- C:\ProgramData\GARMIN\Core Update Service\APP-express-windows-2.3.18.0\GarminExpressInstaller.exe
2014-01-18 18:57:18 A66B365579D8CEBD7F1D4D6B6F7F9373 10284816 ----a-w- C:\Stahování\mbam-setup.exe
2014-01-17 20:05:26 4C4AB9390E4B943D43CA051103DA667F 2002944 ----a-w- C:\Stahování\HousecallLauncher (1).exe
2014-01-17 16:23:05 00C2D68C98FA311C1A80EE33ED846923 36500648 ----a-w- C:\Users\Pepino\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\32.0.1700.76\32.0.1700.76_chrome_installer.exe
2014-01-16 18:23:04 1D0A1FF655C6CF2EA2DE4FB6AA8246AD 9046696 ----a-w- C:\Users\Pepino\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\32.0.1700.76\32.0.1700.76_31.0.1650.63_chrome_updater.exe
2014-01-15 09:54:40 A3094EA13C935427CD210F6F9AAEE6E9 1220608 ----a-w- C:\Users\Pepino\Desktop\FRST.exe
=== C: other files ==
2014-01-18 18:59:49 4470E3C1E0C3378E4CAB137893C12C3A 22856 ----a-w- C:\Windows\System32\drivers\mbam.sys
2014-01-15 10:26:07 1E882889A4314D6DF5DED4F6EC994E72 2349056 ----a-w- C:\Windows\System32\win32k.sys
2014-01-15 10:26:06 EDF2DF71C4F1E13A6AC75F5224DE655A 258560 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbhub.sys
2014-01-15 10:26:06 EDF2DF71C4F1E13A6AC75F5224DE655A 258560 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usb.inf_x86_neutral_4232097e28daf017\usbhub.sys
2014-01-15 10:26:06 EDF2DF71C4F1E13A6AC75F5224DE655A 258560 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2014-01-15 10:26:06 EC2C5AF37B76D7B58C642CB74423DB7A 284672 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbport.sys
2014-01-15 10:26:06 EC2C5AF37B76D7B58C642CB74423DB7A 284672 ----a-w- C:\Windows\System32\drivers\usbport.sys
2014-01-15 10:26:06 D40855F89B69305140BBD7E9A3BA2DA6 43520 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbehci.sys
2014-01-15 10:26:06 D40855F89B69305140BBD7E9A3BA2DA6 43520 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2014-01-15 10:26:06 9828C8D14CC2676421778F0DE638CF97 20480 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbohci.sys
2014-01-15 10:26:06 9828C8D14CC2676421778F0DE638CF97 20480 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2014-01-15 10:26:06 800AABFD625EEFF899F7E5496BDE37AB 24064 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbuhci.sys
2014-01-15 10:26:06 800AABFD625EEFF899F7E5496BDE37AB 24064 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2014-01-15 10:26:06 5DBD4F73E2A52FEED61DBAB3752E329C 240576 ----a-w- C:\Windows\System32\drivers\netio.sys
2014-01-15 10:26:06 0803FBA9FE829D61AE26EC0BCC910C46 76288 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usb.inf_x86_neutral_4232097e28daf017\usbccgp.sys
2014-01-15 10:26:06 0803FBA9FE829D61AE26EC0BCC910C46 76288 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2014-01-15 10:26:05 74F805AB12EB0E3E49E469F19FF02640 6016 ----a-w- C:\Windows\System32\DriverStore\FileRepository\usbport.inf_x86_neutral_d53c05ca022d95f2\usbd.sys
2014-01-15 10:26:05 74F805AB12EB0E3E49E469F19FF02640 6016 ----a-w- C:\Windows\System32\drivers\usbd.sys
======== System Restore Points ========
RP957: 15.1.2014 16:16:13 - Windows Update
RP958: 17.1.2014 20:29:59 - ComboFix created restore point
RP959: 20.1.2014 18:30:09 - OTL Restore Point - 20.1.2014 18:30:05
RP960: 21.1.2014 12:47:44 - Windows Update
RP961: 22.1.2014 9:35:10 - zoek.exe restore point
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-21-523520967-2514350937-3344637787-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Svátky a výročí"="D:\Místní disk\Výročí2000\Vyroci.exe"
"Google Update"="C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"348FAD846955513869AA0AAFB157AEC8F663E556._service_run"="C:\Users\Pepino\AppData\Local\Google\Chrome\Application\chrome.exe --type=service"
"Google Update (1)"="C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"KiesPDLR"="C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Svátky a výročí"="D:\Místní disk\Výročí2000\Vyroci.exe"
"Google Update"="C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"348FAD846955513869AA0AAFB157AEC8F663E556._service_run"="C:\Users\Pepino\AppData\Local\Google\Chrome\Application\chrome.exe --type=service"
"Google Update (1)"="C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"KiesPDLR"="C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"hkey"="HKCU"
"command"="C:\\Program Files\\Samsung\\Kies\\External\\FirmwareUpdate\\KiesPDLR.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe ARM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Adobe ARM"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="APSDaemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATICustomerCare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ATICustomerCare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI\\ATICustomerCare\\ATICustomerCare.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CommonToolkitTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CommonToolkitTray"
"hkey"="HKLM"
"command"="C:\\Program Files\\Fighters\\Tray\\FightersTray.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DT HPW]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DT HPW"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Portrait Displays\\Shared\\DT_startup.exe -HPW"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EEventManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EEventManager"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EPSON PX720WD Series]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EPSON PX720WD Series"
"hkey"="HKCU"
"command"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATIGYE.EXE /FU \"C:\\Users\\Pepino\\AppData\\Local\\Temp\\E_S5294.tmp\" /EF \"HKCU\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EPSON PX820FWD Series]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EPSON PX820FWD Series"
"hkey"="HKCU"
"command"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATIGXE.EXE /FU \"C:\\Windows\\TEMP\\E_SFD16.tmp\" /EF \"HKCU\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\EPSON PX820FWD Series (kopie 1)]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="EPSON PX820FWD Series (kopie 1)"
"hkey"="HKCU"
"command"="C:\\Windows\\system32\\spool\\DRIVERS\\W32X86\\3\\E_FATIGXE.EXE /FU \"C:\\Windows\\TEMP\\E_SCF62.tmp\" /EF \"HKCU\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FreeApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FreeApp"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeApps\\FreeApps.exe\" /autorun"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google+ Auto Backup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Google+ Auto Backup"
"hkey"="HKCU"
"command"="\"C:\\Users\\Pepino\\AppData\\Local\\Programs\\Google\\Google+ Auto Backup\\Google+ Auto Backup.exe\" /autostart"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GoogleDriveSync]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleDriveSync"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Google\\Drive\\googledrivesync.exe\" /autostart"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HDAudDeck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HDAudDeck"
"hkey"="HKLM"
"command"="C:\\Program Files\\VIA\\VIAudioi\\VDeck\\VDeck.exe -r"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LightScribe Control Panel]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LightScribe Control Panel"
"hkey"="HKCU"
"command"="C:\\Program Files\\Common Files\\LightScribe\\LightScribeControlPanel.exe -hidden"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\OM2_Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OM2_Monitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\OLYMPUS\\OLYMPUS Master 2\\FirstStart.exe\" /OM"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\sfagent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sfagent"
"hkey"="HKLM"
"command"="C:\\Program Files\\Fighters\\SPAMfighter\\sfagent.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sidebar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Sidebar"
"hkey"="HKCU"
"command"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SkyDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SkyDrive"
"hkey"="HKCU"
"command"="\"C:\\Users\\Pepino\\AppData\\Local\\Microsoft\\SkyDrive\\SkyDrive.exe\" /background"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SMSTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SMSTray"
"hkey"="HKLM"
"command"="C:\\Program Files\\Samsung\\EmoDio\\SMSTray.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\snpstd]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="snpstd"
"hkey"="HKLM"
"command"="C:\\Windows\\vsnpstd.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\StartCCC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="StartCCC"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\" MSRun"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SWPROguard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SWPROguard"
"hkey"="HKLM"
"command"="C:\\Program Files\\Fighters\\SPYWAREfighter\\swprotray.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VFPROguard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VFPROguard"
"hkey"="HKLM"
"command"="C:\\Program Files\\Fighters\\VIRUSfighter\\vfprotray.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Pepino^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
"path"="C:\\Users\\Pepino\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OpenOffice.org 3.3.lnk"
"backup"="C:\\Windows\\pss\\OpenOffice.org 3.3.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\PROGRA~1\\OPENOF~1.ORG\\program\\QUICKS~1.EXE "
"item"="OpenOffice.org 3.3"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Pepino^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PopTray.lnk]
"backup"="C:\\Windows\\pss\\PopTray.lnk.Startup"
"backupExtension"=".Startup"
"command"="C:\\PROGRA~1\\PopTray\\PopTray.exe "
"item"="PopTray"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AVGIDSAgent]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\avgwd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\BackupStack]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Fax]
==== Other Scheduled Tasks ======================
"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-523520967-2514350937-3344637787-1000Core" [C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-523520967-2514350937-3344637787-1000UA" [C:\Users\Pepino\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\RealUpgradeLogonTaskS-1-5-21-523520967-2514350937-3344637787-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\RealUpgradeScheduledTaskS-1-5-21-523520967-2514350937-3344637787-1000" [C:\Program Files\Real\RealUpgrade\RealUpgrade.exe]
"C:\Windows\system32\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\system32\tasks\SuperEasyDriverUpdaterRunAtStartup" [C:\Program Files\SuperEasy Software\Driver Updater\supereasydu.exe]
"C:\Windows\system32\tasks\Wise Turbo Checker" [C:\Program Files\Wise\Wise Care 365\WiseTurbo.exe]
"C:\Windows\system32\tasks\{107DE489-CFC2-4DB9-BEFA-578B37401B99}" [C:\UCTO2009\UFAND.EXE]
"C:\Windows\system32\tasks\{5B67F373-E755-4796-B7D5-F8C0379C4BCF}" [C:\UCTO2009\UFAND.EXE]
"C:\Windows\system32\tasks\{87A68846-E604-405D-ABC2-8F2F15BC25BD}" [C:\Usti\mu5v3-30\Multi-5.exe]
"C:\Windows\system32\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files\Apple Software Update\SoftwareUpdate.exe]
"C:\Windows\system32\tasks\ASUS\ASUS SIX Engine" [C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe]
"C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"
wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [29.12.2013 17:39]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Visualisateur 3D de 20-20 - %ProfilePath%\extensions\
2020Player_IKEA@2020Technologies.com
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\
cs@dictionaries.addons.mozilla.org
AppDir: C:\Program Files\Mozilla Firefox
- Undetermined - %AppDir%\extensions\staged
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Pepino\AppData\Roaming\Mozilla\Firefox\Profiles\ufhc24fc.default
F891089A6AB9E12FEDEBCC5EC0F40D66 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll - Shockwave Flash
EEEB86077BB4682B3FCFEDA5AED3E396 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.4
BADFB0DCCD9B7E9F2F6EB7954D24EED1 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.4
1153F58FACBC9731AF6CDF313F76DF29 - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.4
9E4F520270BF7301CC24E8FA67791C22 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.4
E50A1DB5DE70D656287511297B42F9F2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.4
C36444D7301A8C881FC7296B092609C7 - C:\Users\Pepino\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
C36444D7301A8C881FC7296B092609C7 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In
3220B1254AEF7A191187EC03F51B3D61 - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
B2576571746839180833E048AC2CCA5C - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
5B4DA1113F240C3F06FFF9D52761528B - C:\Program Files\Google\Picasa3\npPicasa3.dll - Picasa
D7EFF0B98C370E03D7E2593399D9B669 - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll - NVIDIA 3D Vision
75A1232EAC640B782CDD2132B5271AA8 - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll - NVIDIA 3D VISION
DA4E83FE6F229C7108EF5E9671B29260 - C:\Program Files\Garmin GPS Plugin\npGarmin.dll - Garmin Communicator Plug-In
0A1FF0B674E2F268799442A434A63BB3 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
28DFB457A392E782BAA80E780552A8F7 - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
B27CCB1168B1960AEC6E9D3E0E0F0D2A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrlui.dll - Microsoft® Silverlight
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
jfmjfhklogoienhpfnppmbcbjfjnkonk - No path found[]
avast Online Security - Pepino\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
20-20 3D Viewer for IKEA - Pepino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm
Comodo Site Inspector - Pepino\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
"Backup.Old.Start Page"="
http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="
http://www.google.com/search?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="
http://www.google.com/ie"
"Default_Search_URL"="
http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
"Backup.Old.Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="
http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="
http://www.google.com/search?q={searchT ... {startPage}"
==== Reset Google Chrome ======================
C:\Users\Pepino\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Pepino\AppData\Local\COMODO\Dragon\User Data\Default\Preferences was reset successfully
C:\Users\Pepino\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Pepino\AppData\Local\COMODO\Dragon\User Data\Default\Web Data was reset successfully
==== shortcuts on Users Desktops ======================
C:\Users\Pepino\Desktop\Adobe Photoshop 7.0.1 CE.lnk - C:\Program Files\Adobe\Photoshop 7.0 CE\Photoshop.exe
C:\Users\Pepino\Desktop\Audiograbber.lnk - C:\audiograbber\audiograbber.exe
C:\Users\Pepino\Desktop\AVS Media Player.lnk - C:\Program Files\AVS4YOU\AVSMediaPlayer\AVSMediaPlayer.exe
C:\Users\Pepino\Desktop\Disk Google.lnk - C:\Users\Pepino\Disk Google
C:\Users\Pepino\Desktop\DVD Shrink 3.2.lnk - C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe
C:\Users\Pepino\Desktop\DVDFab 7.lnk - C:\Program Files\DVDFab 7\DVDFab.exe
C:\Users\Pepino\Desktop\Free Billiards 2008.lnk - C:\Program Files\FreeGamePick.com\Free Billiards 2008\FreeBilliards2008.exe
C:\Users\Pepino\Desktop\HiJackThis.lnk - C:\Users\Pepino\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
C:\Users\Pepino\Desktop\Microsoft SkyDrive.lnk - C:\Users\Pepino\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Users\Pepino\Desktop\Mrazák.lnk - C:\Users\Pepino\SkyDrive\Mrazák.xlsx
C:\Users\Pepino\Desktop\Ovládací panely.lnk -
C:\Users\Pepino\Desktop\Počítač.lnk -
C:\Users\Pepino\Desktop\Run Ski Challenge 12 (SRF).lnk - D:\Ski Challenge 12 (SRF)\Updater.exe
C:\Users\Pepino\Desktop\Sketch Drawer.lnk - C:\Program Files\Sketch Drawer\SketchDrawer.exe
C:\Users\Pepino\Desktop\Spotify.lnk - C:\Users\Pepino\AppData\Roaming\Spotify\spotify.exe
C:\Users\Pepino\Desktop\Uschovna.cz.lnk - C:\Program Files\Uschovna.cz\Uschovna_cz.exe
C:\Users\Pepino\Desktop\ÚČTO 2013.LNK - C:\UCTO2013\U.BAT
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft Access 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\accicons.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft Excel 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft InfoPath Designer 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\inficon.exe /design
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft InfoPath Filler 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\inficon.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft OneNote 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\joticon.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft Outlook 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\outicon.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft PowerPoint 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pptico.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft Publisher 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\pubs.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\grvicons.exe
C:\Users\Pepino\Desktop\Microsoft Office\Microsoft Word 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
C:\Users\Pepino\Desktop\Microsoft Office\Nástroje systému Microsoft Office 2010\Digitální certifikát pro projekty v jazyce VBA.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe
C:\Users\Pepino\Desktop\Microsoft Office\Nástroje systému Microsoft Office 2010\Galerie médií.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\cagicon.exe
C:\Users\Pepino\Desktop\Microsoft Office\Nástroje systému Microsoft Office 2010\Jazykové předvolby systému Microsoft Office 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\misc.exe
C:\Users\Pepino\Desktop\Microsoft Office\Nástroje systému Microsoft Office 2010\Microsoft Office 2010 Upload Center.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\msouc.exe
C:\Users\Pepino\Desktop\Microsoft Office\Nástroje systému Microsoft Office 2010\Microsoft Office Picture Manager.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\oisicon.exe
C:\Users\UpdatusUser\Desktop\ÚČTO 2013.LNK - C:\UCTO2013\U.BAT
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Ashampoo Burning Studio 2013.lnk - C:\Program Files\Ashampoo\Ashampoo Burning Studio 2013\burningstudio2013.exe
C:\Users\Public\Desktop\Ashampoo Photo Card.lnk - C:\Program Files\Ashampoo\Ashampoo Photo Card\ASHCARD.exe
C:\Users\Public\Desktop\avast Free Antivirus.lnk -
C:\Users\Public\Desktop\calibre - E-book management.lnk - C:\Program Files\Calibre2\calibre.exe
C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner.exe
C:\Users\Public\Desktop\CDSM Designer.lnk - C:\CDSM\CDSM_Designer\MPR500 Pro 5\AlbumMaker.exe
C:\Users\Public\Desktop\Epson Easy Photo Print.lnk - C:\Program Files\Epson Software\Easy Photo Print\EPQuicker.exe
C:\Users\Public\Desktop\EPSON Scan.lnk - C:\Windows\twain_32\escndv\escndv.exe
C:\Users\Public\Desktop\Garmin Express.lnk - C:\Program Files\Garmin\Express\Express.exe
C:\Users\Public\Desktop\GIMP 2.lnk - C:\Program Files\GIMP-2.0\bin\gimp-2.6.exe
C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\Public\Desktop\MyKeyFinder.lnk - C:\Program Files\MyKeyFinder\KeyFinder.exe
C:\Users\Public\Desktop\Photomizer.lnk - C:\Program Files\Engelmann Media\Photomizer\Photomizer.exe
C:\Users\Public\Desktop\Picasa 3.lnk - C:\Program Files\Google\Picasa3\Picasa3.exe
C:\Users\Public\Desktop\Print CD.lnk - C:\Program Files\Epson Software\Print CD\PrintCD.exe
C:\Users\Public\Desktop\rajče průvodce.lnk - C:\Program Files\rajce\rajce.exe
C:\Users\Public\Desktop\Recuva.lnk - C:\Program Files\Recuva\Recuva.exe
C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
C:\Users\Public\Desktop\ViewNX 2.lnk - C:\Program Files\Nikon\ViewNX 2\ViewNX 2\ViewNX2.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk - C:\Users\Pepino\AppData\Roaming\Spotify\spotify.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\Pepino\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup\Google+ Auto Backup.lnk - C:\Users\Pepino\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup\Uninstall Google+ Auto Backup.lnk - C:\Windows\System32\msiexec.exe /x {A50DE037-B5C0-4C8A-8049-B0C576B313D1}
C:\Users\Pepino\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis\HiJackThis.lnk - C:\Users\Pepino\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1029-7B44-AA1000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Burning Studio 2013\Ashampoo Burning Studio 2013 .lnk - C:\Program Files\Ashampoo\Ashampoo Burning Studio 2013\burningstudio2013.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Burning Studio 2013\Nápověda.lnk - C:\Program Files\Ashampoo\Ashampoo Burning Studio 2013\lang\BurningStudio-en-us.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Burning Studio 2013\Odinstalovat aplikaci Ashampoo Burning Studio 2013.lnk - C:\Program Files\Ashampoo\Ashampoo Burning Studio 2013\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Burning Studio 2013\Čti mne.lnk - C:\Program Files\Ashampoo\Ashampoo Burning Studio 2013\readme_en_us.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Photo Card\Ashampoo Photo Card .lnk - C:\Program Files\Ashampoo\Ashampoo Photo Card\ASHCARD.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Photo Card\Nápověda.lnk - C:\Program Files\Ashampoo\Ashampoo Photo Card\Help\APC-en-us.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Photo Card\Odinstalovat aplikaci Ashampoo Photo Card.lnk - C:\Program Files\Ashampoo\Ashampoo Photo Card\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo\Ashampoo Photo Card\Čti mne.lnk - C:\Program Files\Ashampoo\Ashampoo Photo Card\readme_en_us.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast\avast Free Antivirus.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management\calibre - E-book management.lnk - C:\Program Files\Calibre2\calibre.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management\E-book viewer.lnk - C:\Program Files\Calibre2\ebook-viewer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management\Edit E-book.lnk - C:\Program Files\Calibre2\ebook-edit.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management\LRF viewer.lnk - C:\Program Files\Calibre2\lrfviewer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware Help.lnk - C:\Program Files\Malwarebytes' Anti-Malware\mbam.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Odinstalovat aplikaci Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3\Konfigurovat Prohlížeč fotografií Picasa.lnk - C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe /reconfig
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3\Odinstalovat.lnk - C:\Program Files\Google\Picasa3\Uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3\Picasa 3.lnk - C:\Program Files\Google\Picasa3\Picasa3.exe
==== shortcuts in Quick Launch ======================
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DVDFab 7.lnk - C:\Program Files\DVDFab 7\DVDFab.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FLAC To MP3.lnk - C:\FLAC To MP3\flac2mp3.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\keepinhead.lnk - C:\Program Files\JCL Keepinhead\Keepinhead.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk - C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE /recycle
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk - C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk - C:\Windows\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Oracle VM VirtualBox.lnk - C:\Program Files\Oracle\VirtualBox\VirtualBox.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Photomizer.lnk - C:\Program Files\Engelmann Media\Photomizer\Photomizer.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk - C:\Program Files\Google\Picasa3\Picasa3.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\rajče průvodce.lnk - C:\Program Files\rajce\rajce.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - C:\Program Files\Samsung\Kies\Kies.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VideoMizer.lnk - C:\Program Files\VideoMizer\VideoMizer.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\WinX Free DVD to AVI Ripper.lnk - C:\Program Files\Digiarty\WinX_Free_DVD_to_AVI_Ripper\WinX_Free_DVD_to_AVI_Ripper.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Zoner Photo Studio 11.lnk - C:\Program Files\Zoner\Photo Studio 11\Program\Zps.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Word 2010.lnk - C:\Windows\Installer\{91140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\PopTray.lnk - C:\Program Files\PopTray\PopTray.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\Pepino\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\stcd – zástupce.lnk - C:\Windows.old\Program Files\SureThing CD Labeler 5\stcd.exe
C:\Users\Pepino\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe
C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CommonToolkitTray deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON PX820FWD Series deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON PX820FWD Series (kopie 1) deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sfagent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SWPROguard deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VFPROguard deleted successfully
==== HijackThis Entries ======================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Svátky a výročí] D:\Místní disk\Výročí2000\Vyroci.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{21339550-9A90-4808-91A8-6AC1F1C0BCE3}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0189448-912C-424D-897A-E49D7F274B3B}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{21339550-9A90-4808-91A8-6AC1F1C0BCE3}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{21339550-9A90-4808-91A8-6AC1F1C0BCE3}: NameServer = 8.26.56.26,156.154.70.22
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\System32\bgsvcgen.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: SAMSUNG WiseLinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe
==== Empty IE Cache ======================
C:\Users\Pepino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\Pepino\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Pepino\AppData\Local\COMODO\Dragon\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
No Flash Cache Found
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=42 folders=23 16870676 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Users\Pepino\AppData\Local\Temp will be emptied at reboot
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Pepino\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 22.01.2014 at 9:55:00,16 ======================