JRT log :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Microsoft Windows XP x86
Ran by GhostFaceKilla on po 07.04.2014 at 17:22:16,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
~~~ Files
~~~ Folders
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 07.04.2014 at 17:26:50,19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwCleaner log:
# AdwCleaner v3.023 - Report created 07/04/2014 at 17:29:33
# Updated 01/04/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : GhostFaceKilla - GHOSTFACE
# Running from : C:\Documents and Settings\GhostFaceKilla\Plocha\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Google Chrome v33.0.1750.154
[ File : C:\Documents and Settings\GhostFaceKilla\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2383 octets] - [07/04/2014 07:26:48]
AdwCleaner[R1].txt - [2443 octets] - [07/04/2014 13:35:52]
AdwCleaner[R2].txt - [2490 octets] - [07/04/2014 13:38:03]
AdwCleaner[R3].txt - [1074 octets] - [07/04/2014 13:48:39]
AdwCleaner[R4].txt - [1135 octets] - [07/04/2014 17:28:16]
AdwCleaner[S0].txt - [2607 octets] - [07/04/2014 13:39:18]
AdwCleaner[S1].txt - [1057 octets] - [07/04/2014 17:29:33]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1117 octets] ##########
Zoek log:
Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by GhostFaceKilla on po 07.04.2014 at 17:33:32,89.
Microsoft Windows XP Home Edition 5.1.2600 Service Pack 3 x86
Running in: Normal Mode No Internet Access Detected
Launched: C:\Documents and Settings\GhostFaceKilla\Plocha\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
7.4.2014 17:36:48 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Running Processes ======================
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Documents and Settings\GhostFaceKilla\Local Settings\Data aplikací\VNT\vntldr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\{$1284-9213-2940-1289$}\comhost.exe
C:\Program Files\PANDORA.TV\PanService\KMPService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
C:\Program Files\PANDORA.TV\PanService\KMPProcess.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Documents and Settings\GhostFaceKilla\daemonprocess.txt deleted
C:\Documents and Settings\GhostFaceKilla\.android deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\Package Cache deleted
C:\DOCUME~1\GHOSTF~1\NABDKA~1\Programy\Internet Download Manager deleted
"C:\DOCUME~1\ALLUSE~1\DATAAP~1\27218346293184.exe" not deleted
"C:\Program Files\Internet Download Manager\idmmkb.dll" deleted
"C:\Program Files\Internet Download Manager\IDMNetMon.dll" deleted
"C:\Program Files\Internet Download Manager\IDMShellExt.dll" deleted
"C:\Program Files\Internet Download Manager\IEMonitor.exe" deleted
"C:\Program Files\Internet Download Manager" not deleted
======== System Restore Points ========
RP69: 5.2.2014 20:13:46 - Odstraněno Nosferatu
RP70: 5.2.2014 22:48:39 - Installed Asterix and Obelix XXL2
RP71: 6.2.2014 23:38:42 - Kontrolní bod systému
RP72: 9.2.2014 8:27:48 - Installed Morrowind
RP73: 9.2.2014 8:30:03 - Installed TES Construction Set
RP74: 9.2.2014 8:30:53 - Installed Tribunal
RP75: 9.2.2014 8:32:10 - Installed Bloodmoon
RP76: 11.2.2014 1:38:55 - Kontrolní bod systému
RP77: 12.2.2014 3:31:56 - Kontrolní bod systému
RP78: 12.2.2014 19:04:23 - Installed Microsoft Office Professional Plus 2010
RP79: 12.2.2014 19:13:52 - Je nainstalován ovladač tiskárny Send To Microsoft OneNote 2010
RP80: 12.2.2014 19:20:47 - Nainstalováno: Jazyk popisů ovládacích prvků systému Microsoft Office 2010 – čeština
RP81: 13.2.2014 23:05:03 - Kontrolní bod systému
RP82: 15.2.2014 11:09:20 - Removed Morrowind
RP83: 15.2.2014 11:25:01 - Installed Morrowind
RP84: 15.2.2014 11:30:42 - Installed TES Construction Set
RP85: 15.2.2014 11:37:19 - Installed Tribunal
RP86: 15.2.2014 11:40:57 - Installed Bloodmoon
RP87: 15.2.2014 17:04:11 - Removed Morrowind
RP88: 15.2.2014 18:56:31 - Installed Morrowind
RP89: 15.2.2014 19:00:13 - Removed TES Construction Set
RP90: 15.2.2014 19:01:20 - Removed Morrowind
RP91: 15.2.2014 19:07:35 - Installed Morrowind
RP92: 15.2.2014 19:10:59 - Installed TES Construction Set
RP93: 15.2.2014 19:11:42 - Installed Tribunal
RP94: 15.2.2014 19:13:01 - Installed Bloodmoon
RP95: 16.2.2014 13:26:49 - Removed Morrowind
RP96: 16.2.2014 13:28:11 - Installed Morrowind
RP97: 16.2.2014 13:30:39 - Removed TES Construction Set
RP98: 16.2.2014 13:31:46 - Removed Morrowind
RP99: 16.2.2014 13:32:32 - Installed Morrowind
RP100: 16.2.2014 13:34:43 - Installed TES Construction Set
RP101: 16.2.2014 13:35:54 - Removed Morrowind
RP102: 16.2.2014 13:40:41 - Installed Morrowind
RP103: 16.2.2014 13:42:47 - Installed TES Construction Set
RP104: 16.2.2014 13:43:16 - Installed Tribunal
RP105: 16.2.2014 13:45:04 - Installed Bloodmoon
RP106: 16.2.2014 14:06:55 - Removed Morrowind
RP107: 16.2.2014 14:10:05 - Installed Morrowind
RP108: 16.2.2014 14:12:26 - Installed TES Construction Set
RP109: 16.2.2014 14:13:49 - Installed Tribunal
RP110: 16.2.2014 14:15:24 - Installed Bloodmoon
RP111: 17.2.2014 14:17:06 - Kontrolní bod systému
RP112: 18.2.2014 14:20:26 - Kontrolní bod systému
RP113: 19.2.2014 14:31:52 - Kontrolní bod systému
RP114: 21.2.2014 1:06:58 - Kontrolní bod systému
RP115: 22.2.2014 6:11:36 - Kontrolní bod systému
RP116: 23.2.2014 6:35:39 - Kontrolní bod systému
RP117: 24.2.2014 8:46:56 - Kontrolní bod systému
RP118: 25.2.2014 15:45:06 - Kontrolní bod systému
RP119: 27.2.2014 14:42:45 - Kontrolní bod systému
RP120: 1.3.2014 1:25:20 - Kontrolní bod systému
RP121: 2.3.2014 6:50:33 - Kontrolní bod systému
RP122: 3.3.2014 8:40:16 - Kontrolní bod systému
RP123: 4.3.2014 9:27:48 - Kontrolní bod systému
RP124: 4.3.2014 16:50:48 - Nainstalováno: Mc Titan FTB
RP125: 4.3.2014 19:44:23 - Removed Java 7 Update 51
RP126: 4.3.2014 19:45:01 - Installed Java 7 Update 51
RP127: 5.3.2014 23:54:37 - Kontrolní bod systému
RP128: 6.3.2014 11:56:25 - Installed The Floor is Jelly
RP129: 7.4.2014 17:36:48 - zoek.exe restore point
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aaaaipkbmjkakicapiinmamgjlkaeehh - C:\Documents and Settings\All Users\Data aplikacˇ\AskPartnerNetwork\Toolbar\KMPV7\CRX\ToolbarCR.crx[]
jeaohhlajejodfjadcponpnjgkiikocn - C:\Program Files\Internet Download Manager\IDMGCExt.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="
http://www.google.com/search?q={searchT ... {startPage}"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1606980848-152049171-1177238915-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0055C089-8582-441B-A0BF-17B458C2A3A8} deleted successfully
HKEY_USERS\S-1-5-21-1606980848-152049171-1177238915-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0055C089-8582-441B-A0BF-17B458C2A3A8} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\aaaaipkbmjkakicapiinmamgjlkaeehh deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jeaohhlajejodfjadcponpnjgkiikocn deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Download Manager deleted successfully