
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Prosím o kontrolu
Dobrý den,
chtěl bych poprosit o kontrolu logů. Notebook sice funguje, ale zdá se pomalý.
Předem děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2014
Ran by Zdena (administrator) on ZDENA-NOTES on 21-09-2014 11:46:41
Running from C:\Users\Zdena\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(globalUpdate) C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrUI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
() C:\Program Files\Power Manager\PM.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(ShopperPro) C:\Program Files\Common Files\ShopperPro\spbiu.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(DivX, LLC) C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(TorchMedia Inc.) C:\Users\Zdena\AppData\Local\Torch\Update\TorchCrashHandler.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_15_0_0_152_ActiveX.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
(forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-11-22] (Microsoft Corporation)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4349952 2007-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [PowerManager] => C:\Program Files\Power Manager\PM.exe [29696 2007-03-13] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe [3211776 2014-07-22] ()
HKLM\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-08-01] (AVAST Software)
HKLM\...\RunOnce: [FileOpenerPro Uninstall] => cmd /C rd /Q /S "C:\Program Files\FileOpenerPro"
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [T-Mobile Communication Centre] => C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [1355792 2011-03-08] (Gemfor s.r.o.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [TBHostSupport] => "C:\Windows\system32\Rundll32.exe" "C:\Users\Zdena\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin <===== ATTENTION
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe [3211776 2014-07-22] ()
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies App\Datamngr\apcrtldr.dll [488456 2014-08-07] () <===== ATTENTION
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2448} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKCU - {213B6798-9435-4B6F-8AA9-728A976F8A04} URL = http://search.atlas.cz/?q={searchTerms}
SearchScopes: HKCU - {21D06FF9-74FF-4BD8-B47B-5AB1707AE1AE} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2448} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKCU - {CDBFB47B-58A8-4111-BF95-06178DCE326D} URL =
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: XTTBPos00 Class -> {055FD26D-3A88-4e15-963D-DC8493744B1D} -> C:\Program Files\ICQToolbar\toolbaru.dll (IE Toolbar)
BHO: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Object Browser -> {11111111-1111-1111-1111-110311281150} -> C:\Program Files\Object Browser\Object Browser-bho.dll (Object Browser)
BHO: iWebar -> {11111111-1111-1111-1111-110311551110} -> C:\Program Files\iWebar\iWebar-bho.dll (iWebar)
BHO: Sense -> {11111111-1111-1111-1111-110411821192} -> C:\Program Files\Sense\Sense-bho.dll (Object Browser)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: NP Helper Class -> {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} -> C:\Program Files\Internet Saving Optimizer\3.7.0.4550\NPIEAddOn.dll ()
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.7725.1624\swg.dll (Google Inc.)
BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - No Name - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - No File
Toolbar: HKCU - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-be ... canner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD44/JSCDL ... 586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q=
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=a13674-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: TorchVLC -> C:\Users\Zdena\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\user.js
FF SearchPlugin: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Sense - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [2014-06-16]
FF Extension: iWebar - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [2014-06-16]
FF Extension: Object Browser - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [2014-06-16]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\staged [2014-06-23]
FF Extension: Shopper-Pro - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [2014-06-16]
FF Extension: Movies Toolbar (Dist. by Torch Media, Inc.) - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [2014-04-23]
FF Extension: Seznam lištička - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-11-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-10]
FF HKLM\...\Firefox\Extensions: [{2224E955-00E9-4613-A844-CE69FCCAAE91}] - C:\Program Files\Internet Saving Optimizer\3.7.0.4550\FF
FF Extension: NP Helper Class - C:\Program Files\Internet Saving Optimizer\3.7.0.4550\FF [2009-08-30]
FF HKLM\...\Firefox\Extensions: [{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}] - C:\Program Files\Media Access Startup\1.5.6.910\FF
FF Extension: Media Access Startup - C:\Program Files\Media Access Startup\1.5.6.910\FF [2009-08-30]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-05-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-01]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR CustomProfile: C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-06-16]
CHR Extension: (Google Docs) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-09]
CHR Extension: (Google Drive) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-09]
CHR Extension: (YouTube) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-09]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-26]
CHR Extension: (Google Search) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-09]
CHR Extension: (avast! Online Security) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-01]
CHR Extension: (Google Wallet) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-09]
CHR Extension: (DivX Browser Bar) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho [2013-09-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-01]
CHR HKLM\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-09-08]
CHR HKCU\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-09-08]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
R2 ameisvc; C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe [122608 2011-03-08] (Gemfor s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-01] (AVAST Software)
R2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [3573256 2014-08-07] (Torch Media Inc)
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-31] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-31] (globalUpdate) [File not signed]
S2 gupdate1ca8ee972d573a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2010-01-06] (Google Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [234744 2009-02-24] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2006-07-20] () [File not signed]
R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [1812992 2014-07-22] (ShopperPro) [File not signed]
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) [File not signed]
R2 TorchCrashHandler; C:\Users\Zdena\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217032 2014-08-28] (TorchMedia Inc.)
S4 CltMngSvc; C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe [X]
S2 Update sizlsearch; "C:\Program Files\sizlsearch\updatesizlsearch.exe" [X]
S2 Util sizlsearch; "C:\Program Files\sizlsearch\bin\utilsizlsearch.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [53328 2009-11-25] (ALWIL Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [23120 2009-11-25] (ALWIL Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-08-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [114768 2009-11-25] (ALWIL Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [48560 2009-11-25] (ALWIL Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-01] ()
R3 Cam5603D; C:\Windows\System32\Drivers\BisonCam.sys [753456 2007-05-16] ()
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files\Movies App\Datamngr\setmgrc2.cfg [34176 2014-08-07] (Torch Media Inc)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2010-02-22] (MBB Incorporated)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2008-03-31] (Společnost Microsoft)
R3 SIS163u; C:\Windows\System32\DRIVERS\sis163u.sys [218624 2007-05-07] (Silicon Integrated Systems Corp.)
R3 smscirrx; C:\Windows\System32\DRIVERS\smscirrx.sys [40448 2007-02-02] (SMSC)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [25600 2014-07-22] () [File not signed]
S2 SPDRIVER_1.37.0.193; C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [41320 2014-07-22] ()
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R1 WINIO; C:\Windows\system32\WinIo.sys [9336 2007-01-04] (http://www.internals.com) [File not signed]
R1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gt; C:\Windows\System32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys [55232 2014-06-09] (StdLib)
R1 {9d5747ee-0448-4681-8337-1555de75a3b6}t; C:\Windows\System32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}t.sys [55232 2014-06-16] (StdLib)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 11:46 - 2014-09-21 11:47 - 00028911 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:35 - 2014-09-21 11:47 - 00000000 ____D () C:\FRST
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\UC.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\RAR.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKUNZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\LHA.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\ARJ.PIF
2014-09-21 10:09 - 2014-09-21 10:10 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-13 07:29 - 2014-09-13 07:29 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
2014-09-13 07:28 - 2014-09-21 10:46 - 00000000 ____D () C:\ProgramData\Datamngr
2014-09-13 07:27 - 2014-09-13 07:27 - 00000000 ____D () C:\Program Files\Movies App
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-07 19:37 - 2014-09-07 19:37 - 00000867 _____ () C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 11:47 - 2014-09-21 11:46 - 00028911 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 11:47 - 2014-09-21 10:35 - 00000000 ____D () C:\FRST
2014-09-21 11:45 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 11:45 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 11:30 - 2014-06-16 13:25 - 00001696 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-7.job
2014-09-21 11:30 - 2014-06-16 13:24 - 00001682 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-7.job
2014-09-21 11:29 - 2014-06-16 13:24 - 00001440 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-7.job
2014-09-21 11:28 - 2007-11-22 09:15 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-09-21 11:14 - 2010-01-06 18:10 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-21 10:58 - 2013-03-25 18:31 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-21 10:52 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2014-09-21 10:52 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-21 10:51 - 2007-11-22 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-21 10:46 - 2014-09-13 07:28 - 00000000 ____D () C:\ProgramData\Datamngr
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:31 - 2014-09-21 10:30 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:31 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.001
2014-09-21 10:31 - 2008-02-23 09:21 - 00000000 ____D () C:\Users\Zdena
2014-09-21 10:23 - 2014-09-21 10:22 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:12 - 2008-02-23 09:17 - 01790138 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-07-18 09:58 - 00000000 ____D () C:\Program Files (x86)
2014-09-21 10:10 - 2014-09-21 10:09 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-21 10:07 - 2008-02-23 15:33 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001598 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-2.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001586 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-2.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001418 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001328 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.job
2014-09-21 09:49 - 2014-06-16 13:25 - 00002374 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-4.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001764 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-6.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001750 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-6.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001508 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-6.job
2014-09-21 09:49 - 2014-06-16 13:23 - 00004116 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-11.job
2014-09-21 09:47 - 2014-04-23 14:23 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-09-21 09:46 - 2014-06-16 13:26 - 00001688 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-5.job
2014-09-21 09:46 - 2014-06-16 13:26 - 00001676 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-5.job
2014-09-21 09:46 - 2014-06-16 13:23 - 00004114 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-11.job
2014-09-21 09:46 - 2014-06-16 13:23 - 00003788 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.job
2014-09-21 09:45 - 2014-06-16 13:26 - 00001752 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-1.job
2014-09-21 09:45 - 2014-06-16 13:26 - 00001738 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-1.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00002364 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-4.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00002170 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00001496 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-1.job
2014-09-21 09:45 - 2014-06-16 13:24 - 00000922 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-21 09:45 - 2010-01-06 18:10 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-21 09:45 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 09:44 - 2007-11-22 08:02 - 00003308 _____ () C:\Windows\bthservsdp.dat
2014-09-21 09:44 - 2006-11-02 15:01 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-21 09:18 - 2014-08-01 17:09 - 00052670 _____ () C:\Windows\PFRO.log
2014-09-15 21:55 - 2006-11-02 12:33 - 01259320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-15 18:31 - 2014-06-16 13:24 - 00000926 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-14 20:39 - 2013-08-13 15:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 20:23 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-13 07:29 - 2014-09-13 07:29 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
2014-09-13 07:27 - 2014-09-13 07:27 - 00000000 ____D () C:\Program Files\Movies App
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-09 22:29 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.dat
2014-09-09 22:27 - 2008-02-23 09:54 - 00051815 _____ () C:\Windows\KernelMessage
2014-09-07 19:38 - 2014-04-23 14:18 - 00000000 ____D () C:\Users\Zdena\AppData\Local\Torch
2014-09-07 19:37 - 2014-09-07 19:37 - 00000867 _____ () C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-25 06:53 - 2009-10-03 15:34 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
Files to move or delete:
====================
C:\Program Files\Movies App\Datamngr\apcrtldr.dll
C:\Users\Public\MIsetup.exe
Some content of TEMP:
====================
C:\Users\Zdena\AppData\Local\Temp\InstallMonetizer.exe
C:\Users\Zdena\AppData\Local\Temp\ose00000.exe
C:\Users\Zdena\AppData\Local\Temp\ShopperProJSINJFull.exe
C:\Users\Zdena\AppData\Local\Temp\spuad0.exe
C:\Users\Zdena\AppData\Local\Temp\spuad1.exe
C:\Users\Zdena\AppData\Local\Temp\spuad2.exe
C:\Users\Zdena\AppData\Local\Temp\tu17p84.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-1.job => C:\Program Files\Object Browser\Object Browser-codedownloader.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-6.job => C:\Program Files\Object Browser\Object Browser-novainstaller.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-7.job => C:\Program Files\Object Browser\Object Browser-nova.exe
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-1.job => C:\Program Files\iWebar\iWebar-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-11.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-2.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-4.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-5.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-6.job => C:\Program Files\iWebar\iWebar-novainstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-7.job => C:\Program Files\iWebar\iWebar-nova.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-1.job => C:\Program Files\Sense\Sense-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-11.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-2.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-4.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-5.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-6.job => C:\Program Files\Sense\Sense-novainstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-7.job => C:\Program Files\Sense\Sense-nova.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files\RCP\RegCleanPro.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job => C:\Windows\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Zdena\Desktop" je 700 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
chtěl bych poprosit o kontrolu logů. Notebook sice funguje, ale zdá se pomalý.
Předem děkuji.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2014
Ran by Zdena (administrator) on ZDENA-NOTES on 21-09-2014 11:46:41
Running from C:\Users\Zdena\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(globalUpdate) C:\Program Files\globalUpdate\Update\GoogleUpdate.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe
(Torch Media Inc) C:\Program Files\Movies App\Datamngr\DatamngrUI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
() C:\Program Files\Power Manager\PM.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(ShopperPro) C:\Program Files\Common Files\ShopperPro\spbiu.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(DivX, LLC) C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(TorchMedia Inc.) C:\Users\Zdena\AppData\Local\Torch\Update\TorchCrashHandler.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\ieuser.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
(Google Inc.) C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_15_0_0_152_ActiveX.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
(forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-11-22] (Microsoft Corporation)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4349952 2007-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [PowerManager] => C:\Program Files\Power Manager\PM.exe [29696 2007-03-13] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe [3211776 2014-07-22] ()
HKLM\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-08-01] (AVAST Software)
HKLM\...\RunOnce: [FileOpenerPro Uninstall] => cmd /C rd /Q /S "C:\Program Files\FileOpenerPro"
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [T-Mobile Communication Centre] => C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [1355792 2011-03-08] (Gemfor s.r.o.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [TBHostSupport] => "C:\Windows\system32\Rundll32.exe" "C:\Users\Zdena\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin <===== ATTENTION
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe [3211776 2014-07-22] ()
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [YTDownloader] => "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Movies App\Datamngr\apcrtldr.dll [488456 2014-08-07] () <===== ATTENTION
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://www.icq.com/search/results.php?q ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2448} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKCU - {213B6798-9435-4B6F-8AA9-728A976F8A04} URL = http://search.atlas.cz/?q={searchTerms}
SearchScopes: HKCU - {21D06FF9-74FF-4BD8-B47B-5AB1707AE1AE} URL = http://search.seznam.cz/searchScreen?w= ... rms}&mod=f
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2448} URL = http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... 82263&UM=2
SearchScopes: HKCU - {CDBFB47B-58A8-4111-BF95-06178DCE326D} URL =
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: XTTBPos00 Class -> {055FD26D-3A88-4e15-963D-DC8493744B1D} -> C:\Program Files\ICQToolbar\toolbaru.dll (IE Toolbar)
BHO: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Object Browser -> {11111111-1111-1111-1111-110311281150} -> C:\Program Files\Object Browser\Object Browser-bho.dll (Object Browser)
BHO: iWebar -> {11111111-1111-1111-1111-110311551110} -> C:\Program Files\iWebar\iWebar-bho.dll (iWebar)
BHO: Sense -> {11111111-1111-1111-1111-110411821192} -> C:\Program Files\Sense\Sense-bho.dll (Object Browser)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: NP Helper Class -> {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} -> C:\Program Files\Internet Saving Optimizer\3.7.0.4550\NPIEAddOn.dll ()
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll (Goobzo Ltd.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.7725.1624\swg.dll (Google Inc.)
BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - No Name - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - No File
Toolbar: HKCU - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-be ... canner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD44/JSCDL ... 586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FF DefaultSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q=
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4
FF Keyword.URL: hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=a13674-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: TorchVLC -> C:\Users\Zdena\AppData\Local\Torch\Plugins\Video\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\user.js
FF SearchPlugin: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Sense - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [2014-06-16]
FF Extension: iWebar - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [2014-06-16]
FF Extension: Object Browser - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [2014-06-16]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\staged [2014-06-23]
FF Extension: Shopper-Pro - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [2014-06-16]
FF Extension: Movies Toolbar (Dist. by Torch Media, Inc.) - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [2014-04-23]
FF Extension: Seznam lištička - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-11-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-10]
FF HKLM\...\Firefox\Extensions: [{2224E955-00E9-4613-A844-CE69FCCAAE91}] - C:\Program Files\Internet Saving Optimizer\3.7.0.4550\FF
FF Extension: NP Helper Class - C:\Program Files\Internet Saving Optimizer\3.7.0.4550\FF [2009-08-30]
FF HKLM\...\Firefox\Extensions: [{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC}] - C:\Program Files\Media Access Startup\1.5.6.910\FF
FF Extension: Media Access Startup - C:\Program Files\Media Access Startup\1.5.6.910\FF [2009-08-30]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-05-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-01]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\37.0.2062.120\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR CustomProfile: C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-06-16]
CHR Extension: (Google Docs) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-09]
CHR Extension: (Google Drive) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-09]
CHR Extension: (YouTube) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-09]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-26]
CHR Extension: (Google Search) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-09]
CHR Extension: (avast! Online Security) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-01]
CHR Extension: (Google Wallet) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-09]
CHR Extension: (DivX Browser Bar) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho [2013-09-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-01]
CHR HKLM\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-09-08]
CHR HKCU\...\Chrome\Extension: [pkmpcdbgnfjfeelcpebpkflcmbkclfho] - C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx [2013-09-08]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
R2 ameisvc; C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe [122608 2011-03-08] (Gemfor s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-01] (AVAST Software)
R2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [3573256 2014-08-07] (Torch Media Inc)
S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-31] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-31] (globalUpdate) [File not signed]
S2 gupdate1ca8ee972d573a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2010-01-06] (Google Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S2 ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [234744 2009-02-24] ()
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2006-07-20] () [File not signed]
R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [1812992 2014-07-22] (ShopperPro) [File not signed]
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) [File not signed]
R2 TorchCrashHandler; C:\Users\Zdena\AppData\Local\Torch\Update\TorchCrashHandler.exe [1217032 2014-08-28] (TorchMedia Inc.)
S4 CltMngSvc; C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe [X]
S2 Update sizlsearch; "C:\Program Files\sizlsearch\updatesizlsearch.exe" [X]
S2 Util sizlsearch; "C:\Program Files\sizlsearch\bin\utilsizlsearch.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [53328 2009-11-25] (ALWIL Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [23120 2009-11-25] (ALWIL Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-08-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [114768 2009-11-25] (ALWIL Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [48560 2009-11-25] (ALWIL Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-01] ()
R3 Cam5603D; C:\Windows\System32\Drivers\BisonCam.sys [753456 2007-05-16] ()
R1 F06DEFF2-5B9C-490D-910F-35D3A91196222; C:\Program Files\Movies App\Datamngr\setmgrc2.cfg [34176 2014-08-07] (Torch Media Inc)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2010-02-22] (MBB Incorporated)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2008-03-31] (Společnost Microsoft)
R3 SIS163u; C:\Windows\System32\DRIVERS\sis163u.sys [218624 2007-05-07] (Silicon Integrated Systems Corp.)
R3 smscirrx; C:\Windows\System32\DRIVERS\smscirrx.sys [40448 2007-02-02] (SMSC)
R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [25600 2014-07-22] () [File not signed]
S2 SPDRIVER_1.37.0.193; C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [41320 2014-07-22] ()
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R1 WINIO; C:\Windows\system32\WinIo.sys [9336 2007-01-04] (http://www.internals.com) [File not signed]
R1 {9d5747ee-0448-4681-8337-1555de75a3b6}Gt; C:\Windows\System32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys [55232 2014-06-09] (StdLib)
R1 {9d5747ee-0448-4681-8337-1555de75a3b6}t; C:\Windows\System32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}t.sys [55232 2014-06-16] (StdLib)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 11:46 - 2014-09-21 11:47 - 00028911 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:35 - 2014-09-21 11:47 - 00000000 ____D () C:\FRST
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\UC.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\RAR.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKUNZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\LHA.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\ARJ.PIF
2014-09-21 10:09 - 2014-09-21 10:10 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-13 07:29 - 2014-09-13 07:29 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
2014-09-13 07:28 - 2014-09-21 10:46 - 00000000 ____D () C:\ProgramData\Datamngr
2014-09-13 07:27 - 2014-09-13 07:27 - 00000000 ____D () C:\Program Files\Movies App
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-07 19:37 - 2014-09-07 19:37 - 00000867 _____ () C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 11:47 - 2014-09-21 11:46 - 00028911 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 11:47 - 2014-09-21 10:35 - 00000000 ____D () C:\FRST
2014-09-21 11:45 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 11:45 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 11:30 - 2014-06-16 13:25 - 00001696 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-7.job
2014-09-21 11:30 - 2014-06-16 13:24 - 00001682 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-7.job
2014-09-21 11:29 - 2014-06-16 13:24 - 00001440 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-7.job
2014-09-21 11:28 - 2007-11-22 09:15 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-09-21 11:14 - 2010-01-06 18:10 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-21 10:58 - 2013-03-25 18:31 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-21 10:52 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2014-09-21 10:52 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-21 10:51 - 2007-11-22 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-21 10:46 - 2014-09-13 07:28 - 00000000 ____D () C:\ProgramData\Datamngr
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:31 - 2014-09-21 10:30 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:31 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.001
2014-09-21 10:31 - 2008-02-23 09:21 - 00000000 ____D () C:\Users\Zdena
2014-09-21 10:23 - 2014-09-21 10:22 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:12 - 2008-02-23 09:17 - 01790138 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-07-18 09:58 - 00000000 ____D () C:\Program Files (x86)
2014-09-21 10:10 - 2014-09-21 10:09 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-21 10:07 - 2008-02-23 15:33 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001598 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-2.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001586 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-2.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001418 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.job
2014-09-21 09:49 - 2014-06-16 13:26 - 00001328 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.job
2014-09-21 09:49 - 2014-06-16 13:25 - 00002374 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-4.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001764 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-6.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001750 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-6.job
2014-09-21 09:49 - 2014-06-16 13:24 - 00001508 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-6.job
2014-09-21 09:49 - 2014-06-16 13:23 - 00004116 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-11.job
2014-09-21 09:47 - 2014-04-23 14:23 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-09-21 09:46 - 2014-06-16 13:26 - 00001688 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-5.job
2014-09-21 09:46 - 2014-06-16 13:26 - 00001676 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-5.job
2014-09-21 09:46 - 2014-06-16 13:23 - 00004114 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-11.job
2014-09-21 09:46 - 2014-06-16 13:23 - 00003788 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.job
2014-09-21 09:45 - 2014-06-16 13:26 - 00001752 _____ () C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-1.job
2014-09-21 09:45 - 2014-06-16 13:26 - 00001738 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-1.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00002364 _____ () C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-4.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00002170 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.job
2014-09-21 09:45 - 2014-06-16 13:25 - 00001496 _____ () C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-1.job
2014-09-21 09:45 - 2014-06-16 13:24 - 00000922 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-09-21 09:45 - 2010-01-06 18:10 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-21 09:45 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 09:44 - 2007-11-22 08:02 - 00003308 _____ () C:\Windows\bthservsdp.dat
2014-09-21 09:44 - 2006-11-02 15:01 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-21 09:18 - 2014-08-01 17:09 - 00052670 _____ () C:\Windows\PFRO.log
2014-09-15 21:55 - 2006-11-02 12:33 - 01259320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-15 18:31 - 2014-06-16 13:24 - 00000926 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-09-14 20:39 - 2013-08-13 15:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 20:23 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-13 07:29 - 2014-09-13 07:29 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
2014-09-13 07:27 - 2014-09-13 07:27 - 00000000 ____D () C:\Program Files\Movies App
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-09 22:29 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.dat
2014-09-09 22:27 - 2008-02-23 09:54 - 00051815 _____ () C:\Windows\KernelMessage
2014-09-07 19:38 - 2014-04-23 14:18 - 00000000 ____D () C:\Users\Zdena\AppData\Local\Torch
2014-09-07 19:37 - 2014-09-07 19:37 - 00000867 _____ () C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-25 06:53 - 2009-10-03 15:34 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
Files to move or delete:
====================
C:\Program Files\Movies App\Datamngr\apcrtldr.dll
C:\Users\Public\MIsetup.exe
Some content of TEMP:
====================
C:\Users\Zdena\AppData\Local\Temp\InstallMonetizer.exe
C:\Users\Zdena\AppData\Local\Temp\ose00000.exe
C:\Users\Zdena\AppData\Local\Temp\ShopperProJSINJFull.exe
C:\Users\Zdena\AppData\Local\Temp\spuad0.exe
C:\Users\Zdena\AppData\Local\Temp\spuad1.exe
C:\Users\Zdena\AppData\Local\Temp\spuad2.exe
C:\Users\Zdena\AppData\Local\Temp\tu17p84.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-1.job => C:\Program Files\Object Browser\Object Browser-codedownloader.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-11.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-2.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-4.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.job => C:\Program Files\Object Browser\327d2df4-c511-4c48-bb70-05c1d5f0c967-5.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-6.job => C:\Program Files\Object Browser\Object Browser-novainstaller.exe
Task: C:\Windows\Tasks\327d2df4-c511-4c48-bb70-05c1d5f0c967-7.job => C:\Program Files\Object Browser\Object Browser-nova.exe
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-1.job => C:\Program Files\iWebar\iWebar-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-11.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-2.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-4.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-5.job => C:\Program Files\iWebar\60456fd6-279d-4c3f-9601-a636b52de8b8-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-6.job => C:\Program Files\iWebar\iWebar-novainstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\60456fd6-279d-4c3f-9601-a636b52de8b8-7.job => C:\Program Files\iWebar\iWebar-nova.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-1.job => C:\Program Files\Sense\Sense-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-11.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-2.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-4.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-5.job => C:\Program Files\Sense\f1a726d4-098d-4503-ac48-1ea5d300b528-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-6.job => C:\Program Files\Sense\Sense-novainstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\f1a726d4-098d-4503-ac48-1ea5d300b528-7.job => C:\Program Files\Sense\Sense-nova.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files\RCP\RegCleanPro.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job => C:\Windows\system32\msfeedssync.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
==================== Security Center ==================
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Zdena\Desktop" je 700 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (9.47 KiB) Staženo 45 x
Re: Prosím o kontrolu
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner


- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
Zde jsou logy. Jen bych dodal, že se mi po tom restartu podařilo notebook (resp. Windows) nastartovat až na třetí pokus. Snad to ale bude dobré.
AdwCleaner:
# AdwCleaner v3.310 - Report created 21/09/2014 at 15:56:22
# Updated 12/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium (32 bits)
# Username : Zdena - ZDENA-NOTES
# Running from : C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : CltMngSvc
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : ICQ Service
Service Deleted : SPBIUpd
Service Deleted : SPBIUpdd
[#] Service Deleted : torchcrashhandler
[#] Service Deleted : Update sizlsearch
[#] Service Deleted : Util sizlsearch
[#] Service Deleted : {9d5747ee-0448-4681-8337-1555de75a3b6}Gt
[#] Service Deleted : {9d5747ee-0448-4681-8337-1555de75a3b6}t
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\ProgramData\DataMngr
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\ShopperPro
Folder Deleted : C:\ProgramData\AlawarWrapper
[!] Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\Internet Saving Optimizer
Folder Deleted : C:\Program Files\iWebar
[!] Folder Deleted : C:\Program Files\Movies App
Folder Deleted : C:\Program Files\Object Browser
Folder Deleted : C:\Program Files\Sense
Folder Deleted : C:\Program Files\ShopperPro
Folder Deleted : C:\Program Files\Tbccint
Folder Deleted : C:\Program Files\Common Files\ShopperPro
Folder Deleted : C:\Windows\system32\SearchProtect
Folder Deleted : C:\Users\Zdena\AppData\Local\Conduit
Folder Deleted : C:\Users\Zdena\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Zdena\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Zdena\AppData\Local\SearchProtect
Folder Deleted : C:\Users\Zdena\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\Zdena\AppData\Local\torch
Folder Deleted : C:\Users\Zdena\AppData\Local\WhiteListing
Folder Deleted : C:\Users\Zdena\AppData\Local\Temp\Conduit
Folder Deleted : C:\Users\Zdena\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\Zdena\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
File Deleted : C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx
File Deleted : C:\Windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys
File Deleted : C:\Windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}t.sys
File Deleted : C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml
File Deleted : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : ASP
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : ShopperPro
Task Deleted : ShopperProJSUpd
Task Deleted : SPDriver
Task Deleted : YTDownloader
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-1
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-11
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-2
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-4
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-5
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-6
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-7
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-1
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-11
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-2
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-4
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-5
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-6
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-7
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-1
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-11
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-2
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-4
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-5
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-6
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{2224e955-00e9-4613-a844-ce69fccaae91}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [TBHostSupport]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.EasyHideBtn
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.EasyHideBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.Localizer
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.Localizer.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighter
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighter.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighterStatistics
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighterStatistics.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SkypeIEHelper
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SkypeIEHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SNameProxy
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SNameProxy.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SPDriver]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\TorchVLC
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\XTTB00001
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.XTTBPos00
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.XTTBPos00.1
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.XTTB00001
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.XTTB00001.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{937936AF-28CA-4973-B8AE-F250406149A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4BD2D6C3-31DC-B947-23D0-DC52EC4F0C4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C28A0312-C403-417B-A425-A915BC0519CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{5617ECA9-488D-4BA2-8562-9710B9AB78D2}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\APNDTX
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\ICQToolbar
Key Deleted : HKCU\Software\ShopperPro
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Deleted : HKCU\Software\AppDataLow\Software\DoubleD
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Deleted : HKCU\Software\AppDataLow\Software\iWebar
Key Deleted : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Deleted : HKCU\Software\AppDataLow\Software\Object Browser
Key Deleted : HKCU\Software\AppDataLow\Software\Sense
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\iWebar
Key Deleted : HKLM\SOFTWARE\Media Access Startup
Key Deleted : HKLM\SOFTWARE\Object Browser
Key Deleted : HKLM\SOFTWARE\Sense
Key Deleted : HKLM\SOFTWARE\ShopperPro
Key Deleted : HKLM\SOFTWARE\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ICQToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\iWebar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Object Browser
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Sense
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShopperPro
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v7.0.6000.17037
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v26.0 (cs)
[ File : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4");
-\\ Google Chrome v37.0.2062.120
[ File : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_uid=7446414422814117&apn_dtid=TCH001&o=APN10648&apn_ptnrs=AGI&q={searchTerms}
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_uid=7446414422814117&apn_dtid=TCH001&o=APN10648&apn_ptnrs=AGI&q={searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
*************************
AdwCleaner[R0].txt - [20527 octets] - [21/09/2014 15:54:28]
AdwCleaner[S0].txt - [19677 octets] - [21/09/2014 15:56:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19738 octets] ##########
JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.9 (09.20.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Zdena on ne 21.09.2014 at 14:42:07,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Bar
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
TBHostSupport REG_SZ "C:\Windows\system32\Rundll32.exe" "C:\Users\Zdena\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\icq service.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\pc optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update sizlsearch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util sizlsearch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\datamngr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\explorerbar.funexplorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\explorerbar.funexplorer.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\icqtoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322282250}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322552210}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422822292}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355285550}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355555510}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455825592}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366556610}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466826692}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344284450}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444824492}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3288691
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550355285550}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344284450}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444824492}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611211180}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{21D06FF9-74FF-4BD8-B47B-5AB1707AE1AE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2448}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2448}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
~~~ Files
Successfully deleted: [File] "C:\Windows\Tasks\RegClean Pro_UPDATES.job"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_api.ciuvo.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_api.ciuvo.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\https_inst.shoppingate.info_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\https_inst.shoppingate.info_0.localstorage-journal"
Successfully deleted: [File] "C:\Windows\system32\roboot.exe"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\conduit"
Failed to delete: [Folder] "C:\ProgramData\datamngr"
Successfully deleted: [Folder] "C:\ProgramData\pc optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\ProgramData\torchcrashhandler"
Failed to delete: [Folder] "C:\ProgramData\application data\datamngr"
Successfully deleted: [Folder] "C:\Users\Zdena\AppData\Roaming\systweak"
Successfully deleted: [Folder] "\searchprotect"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\media access startup"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\icq6toolbar"
Successfully deleted: [Folder] "C:\Program Files\icqtoolbar"
Successfully deleted: [Folder] "C:\Program Files\media access startup"
Successfully deleted: [Folder] "C:\Program Files\movies toolbar"
Successfully deleted: [Folder] "C:\Program Files\sizlsearch"
Successfully deleted: [Folder] "C:\Program Files\speeditup free"
~~~ FireFox
Successfully deleted: [File] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\user.js
Successfully deleted: [File] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\searchplugins\ask.xml
Successfully deleted: [Folder] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com
Successfully deleted: [Folder] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\extensions\staged
Successfully deleted the following from C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\prefs.js
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_646958.value", "%22function%20startAskCom%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("keyword.url", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q="
user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4");
user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=a13674-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q="
Emptied folder: C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\minidumps [4 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Zdena\appdata\local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 21.09.2014 at 15:51:57,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwCleaner:
# AdwCleaner v3.310 - Report created 21/09/2014 at 15:56:22
# Updated 12/09/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium (32 bits)
# Username : Zdena - ZDENA-NOTES
# Running from : C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : CltMngSvc
[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A91196222
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : ICQ Service
Service Deleted : SPBIUpd
Service Deleted : SPBIUpdd
[#] Service Deleted : torchcrashhandler
[#] Service Deleted : Update sizlsearch
[#] Service Deleted : Util sizlsearch
[#] Service Deleted : {9d5747ee-0448-4681-8337-1555de75a3b6}Gt
[#] Service Deleted : {9d5747ee-0448-4681-8337-1555de75a3b6}t
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\ProgramData\DataMngr
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\ShopperPro
Folder Deleted : C:\ProgramData\AlawarWrapper
[!] Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\Internet Saving Optimizer
Folder Deleted : C:\Program Files\iWebar
[!] Folder Deleted : C:\Program Files\Movies App
Folder Deleted : C:\Program Files\Object Browser
Folder Deleted : C:\Program Files\Sense
Folder Deleted : C:\Program Files\ShopperPro
Folder Deleted : C:\Program Files\Tbccint
Folder Deleted : C:\Program Files\Common Files\ShopperPro
Folder Deleted : C:\Windows\system32\SearchProtect
Folder Deleted : C:\Users\Zdena\AppData\Local\Conduit
Folder Deleted : C:\Users\Zdena\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Zdena\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Zdena\AppData\Local\SearchProtect
Folder Deleted : C:\Users\Zdena\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\Zdena\AppData\Local\torch
Folder Deleted : C:\Users\Zdena\AppData\Local\WhiteListing
Folder Deleted : C:\Users\Zdena\AppData\Local\Temp\Conduit
Folder Deleted : C:\Users\Zdena\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\Zdena\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\Zdena\AppData\Roaming\FirefoxToolbar
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF}
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com
Folder Deleted : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com
File Deleted : C:\Users\Zdena\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx
File Deleted : C:\Windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}Gt.sys
File Deleted : C:\Windows\system32\drivers\{9d5747ee-0448-4681-8337-1555de75a3b6}t.sys
File Deleted : C:\Users\Zdena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Torch.lnk
File Deleted : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml
File Deleted : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : ASP
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : ShopperPro
Task Deleted : ShopperProJSUpd
Task Deleted : SPDriver
Task Deleted : YTDownloader
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-1
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-11
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-2
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-4
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-5
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-6
Task Deleted : 327d2df4-c511-4c48-bb70-05c1d5f0c967-7
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-1
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-11
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-2
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-4
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-5
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-6
Task Deleted : 60456fd6-279d-4c3f-9601-a636b52de8b8-7
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-1
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-11
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-2
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-4
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-5
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-6
Task Deleted : f1a726d4-098d-4503-ac48-1ea5d300b528-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{2224e955-00e9-4613-a844-ce69fccaae91}]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [TBHostSupport]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ShopperPro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO
Key Deleted : HKLM\SOFTWARE\Classes\ShopperPro.ShopperProBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.EasyHideBtn
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.EasyHideBtn.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.Localizer
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.Localizer.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighter
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighter.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighterStatistics
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.NameHighlighterStatistics.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SkypeIEHelper
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SkypeIEHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SNameProxy
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.SNameProxy.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SPDriver]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\TorchVLC
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKCU\Software\XTTB00001
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.XTTBPos00
Key Deleted : HKLM\SOFTWARE\Classes\ToolBand.XTTBPos00.1
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.IEToolbar
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.IEToolbar.1
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.XTTB00001
Key Deleted : HKLM\SOFTWARE\Classes\XTTB00001.XTTB00001.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{937936AF-28CA-4973-B8AE-F250406149A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4BD2D6C3-31DC-B947-23D0-DC52EC4F0C4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C28A0312-C403-417B-A425-A915BC0519CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{5617ECA9-488D-4BA2-8562-9710B9AB78D2}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Key Deleted : HKCU\Software\APNDTX
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\ICQToolbar
Key Deleted : HKCU\Software\ShopperPro
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Deleted : HKCU\Software\AppDataLow\Software\DoubleD
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Deleted : HKCU\Software\AppDataLow\Software\iWebar
Key Deleted : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Deleted : HKCU\Software\AppDataLow\Software\Object Browser
Key Deleted : HKCU\Software\AppDataLow\Software\Sense
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\iWebar
Key Deleted : HKLM\SOFTWARE\Media Access Startup
Key Deleted : HKLM\SOFTWARE\Object Browser
Key Deleted : HKLM\SOFTWARE\Sense
Key Deleted : HKLM\SOFTWARE\ShopperPro
Key Deleted : HKLM\SOFTWARE\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ICQToolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\iWebar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Object Browser
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Sense
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShopperPro
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Sukoku
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\torch
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browsers ] *****
-\\ Internet Explorer v7.0.6000.17037
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v26.0 (cs)
[ File : C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4");
-\\ Google Chrome v37.0.2062.120
[ File : C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_uid=7446414422814117&apn_dtid=TCH001&o=APN10648&apn_ptnrs=AGI&q={searchTerms}
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_uid=7446414422814117&apn_dtid=TCH001&o=APN10648&apn_ptnrs=AGI&q={searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
*************************
AdwCleaner[R0].txt - [20527 octets] - [21/09/2014 15:54:28]
AdwCleaner[S0].txt - [19677 octets] - [21/09/2014 15:56:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19738 octets] ##########
JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.9 (09.20.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Zdena on ne 21.09.2014 at 14:42:07,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Bar
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
TBHostSupport REG_SZ "C:\Windows\system32\Rundll32.exe" "C:\Users\Zdena\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\icq service.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\pc optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\torch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update sizlsearch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util sizlsearch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\datamngr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\torch
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\explorerbar.funexplorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\explorerbar.funexplorer.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\icqtoolbar.iehook.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\searchquiehelper.dnsguard.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\icqtoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0032850.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0035510.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048292.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322282250}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220322552210}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422822292}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355285550}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550355555510}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455825592}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660366556610}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466826692}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344284450}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444824492}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0032850.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0035510.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048292.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3288691
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550355285550}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550355555510}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455825592}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366286650}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660366556610}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466826692}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344284450}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440344554410}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444824492}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611211180}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{21D06FF9-74FF-4BD8-B47B-5AB1707AE1AE}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2448}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2448}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
~~~ Files
Successfully deleted: [File] "C:\Windows\Tasks\RegClean Pro_UPDATES.job"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_api.ciuvo.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_api.ciuvo.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_app.mam.conduit.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\https_inst.shoppingate.info_0.localstorage"
Successfully deleted: [File] "C:\Users\Zdena\appdata\local\google\chrome\user data\default\local storage\https_inst.shoppingate.info_0.localstorage-journal"
Successfully deleted: [File] "C:\Windows\system32\roboot.exe"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\conduit"
Failed to delete: [Folder] "C:\ProgramData\datamngr"
Successfully deleted: [Folder] "C:\ProgramData\pc optimizer pro"
Successfully deleted: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\ProgramData\torchcrashhandler"
Failed to delete: [Folder] "C:\ProgramData\application data\datamngr"
Successfully deleted: [Folder] "C:\Users\Zdena\AppData\Roaming\systweak"
Successfully deleted: [Folder] "\searchprotect"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Users\Zdena\appdata\locallow\media access startup"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\icq6toolbar"
Successfully deleted: [Folder] "C:\Program Files\icqtoolbar"
Successfully deleted: [Folder] "C:\Program Files\media access startup"
Successfully deleted: [Folder] "C:\Program Files\movies toolbar"
Successfully deleted: [Folder] "C:\Program Files\sizlsearch"
Successfully deleted: [Folder] "C:\Program Files\speeditup free"
~~~ FireFox
Successfully deleted: [File] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\user.js
Successfully deleted: [File] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\searchplugins\ask.xml
Successfully deleted: [Folder] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com
Successfully deleted: [Folder] C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\extensions\staged
Successfully deleted the following from C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\prefs.js
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_646958.value", "%22function%20startAskCom%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("keyword.url", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=n12284-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q="
user_pref("browser.startup.homepage", "hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4");
user_pref("keyword.URL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=348&systemid=448&v=a13674-326&apn_dtid=TCH001&apn_ptnrs=AGI&apn_uid=7446414422814117&o=APN10648&q="
Emptied folder: C:\Users\Zdena\AppData\Roaming\mozilla\firefox\profiles\tm736s2j.default\minidumps [4 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Zdena\appdata\local\Google\Chrome\User Data\Default\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on ne 21.09.2014 at 15:51:57,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Prosím o kontrolu


- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;
- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
Zoek.exe v5.0.0.0 Updated 20-September-2014
Tool run by Zdena on ne 21.09.2014 at 21:33:55,58.
Microsoft® Windows Vista™ Home Premium 6.0.6000 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Zdena\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
21.9.2014 21:38:35 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
user_pref("browser.search.defaultenginename", "Google");
Added to C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
user.js not found
---- Lines ask.com removed from prefs.js ----
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
---- Lines www.search removed from prefs.js ----
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- Lines a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 removed from prefs.js ----
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.active", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.addressbar", "NA");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.addressbarenhanced", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb.was_copied", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb_dbWasSet", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb.was_copied", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.backgroundver", 1);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.certdomaininstaller", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallationTime.value", "%221402917792%2
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.description", ".");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.domain", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.enablesearch", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.homepage", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.changeprevious", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.iframe", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.InstallationThankYouPage", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.InstallationTime", 1402917792);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb._installer_additional_info.expiration
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb._installer_additional_info.value", "%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_appVer.value", "65");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_lastVersion.value", "0");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.lastDailyReport", "1403503716204");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.lastUpdate", "1403503694227");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.manifesturl", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.name", "Sense");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.newtab", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.opensearch", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.pluginsversion", 60);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.publisher", "Object Browser");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.searchstatus", 0);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.setnewtab", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.thankyou", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.updateinterval", 360);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.ver", 65);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.apps", "48292");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.cid", 48292);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.firstrun", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.hadappinstalled", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.installationdate", 1403503704);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.installerAdditionalInfo", "{\"asw\":[131072, 8519685,
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.modetype", "production");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.reportInstall", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.statsDailyCounter", 1);
---- Lines a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510 removed from prefs.js ----
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.active", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.addressbar", "NA");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.addressbarenhanced", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb.was_copied", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb_dbWasSet", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb.was_copied", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.backgroundver", 1);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.certdomaininstaller", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallationTime.value", "%221402917792%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.uc.expiration", "Mon Jul 07 2014 08:08:45
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.uc.value", "%22%5C%22CZ%5C%22%22");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.description", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.domain", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.enablesearch", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.homepage", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.changeprevious", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.iframe", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.InstallationThankYouPage", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.InstallationTime", 1402917792);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb._installer_additional_info.expiration
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb._installer_additional_info.value", "%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_appVer.value", "310");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_lastVersion.value", "28");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_183015.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_196378.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353989.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353990.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353991.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_376579.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_376579.value", "%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_483924.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_483925.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_534129.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_646958.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.lastDailyReport", "1403503716093");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.lastUpdate", "1403503696315");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.manifesturl", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.name", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.newtab", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.opensearch", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.pluginsversion", 143);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.publisher", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.searchstatus", 0);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.setnewtab", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.thankyou", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.updateinterval", 360);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.ver", 310);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.apps", "35510");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.cid", 35510);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.firstrun", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.hadappinstalled", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.installationdate", 1403503704);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.installerAdditionalInfo", "{\"asw\":[131072, 8519685,
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.modetype", "production");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.reportInstall", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.statsDailyCounter", 1);
---- Lines a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850 removed from prefs.js ----
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754ca
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754ca
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.active", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.addressbar", "NA");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.addressbarenhanced", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb.was_copied", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb_dbWasSet", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb.was_copied", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.backgroundver", 1);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.certdomaininstaller", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallationTime.value", "%221402917784%2
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.uc.expiration", "Mon Jul 07 2014 08:08:53
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.uc.value", "%22%5C%22CZ%5C%22%22");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.description", "Browser enhancer");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.domain", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.enablesearch", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.homepage", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.changeprevious", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.iframe", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.InstallationThankYouPage", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.InstallationTime", 1402917784);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb._installer_additional_info.expiration
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb._installer_additional_info.value", "%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_appVer.value", "206");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.lastDailyReport", "1403503730219");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.lastUpdate", "1403503716042");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.manifesturl", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.name", "Object Browser");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.newtab", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.opensearch", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.pluginsversion", 170);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.publisher", "Object Browser");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.searchstatus", 0);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.setnewtab", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.thankyou", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.updateinterval", 360);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.ver", 206);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.apps", "32850");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.cid", 32850);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.firstrun", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.hadappinstalled", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.installationdate", 1403503704);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.installerAdditionalInfo", "{\"asw\":[131072, 131077, 0
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.modetype", "production");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.reportInstall", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.statsDailyCounter", 1);
---- Lines {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\
---- FireFox user.js and prefs.js backups ----
prefs_22.09.2014_0006_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted
C:\Program Files\GUT314D.tmp deleted
C:\Program Files\GUM312D.tmp deleted
C:\Users\Zdena\AppData\Roaming\ICQ Toolbar deleted
C:\PROGRA~2\spds90.txt deleted
C:\PROGRA~2\ICQ deleted
C:\PROGRA~2\ProductData deleted
C:\Users\Zdena\AppData\Local\CRE deleted
C:\Users\Zdena\AppData\Local\CrashRpt deleted
C:\Users\Public\MIsetup.exe deleted
C:\Users\Public\Documents\ShopperPro deleted
C:\Users\Zdena\Downloads\StartDownload (1).exe deleted
C:\Users\Zdena\Downloads\StartDownload (2).exe deleted
C:\Users\Zdena\Downloads\StartDownload.exe deleted
C:\Users\Zdena\AppData\LocalLow\torchmediamoviestoolbar181 deleted
C:\Windows\system32\Tasks\SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 deleted
C:\Users\Public\Documents\AlawarWrapper deleted
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\torchmediamoviestoolbar181 deleted
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [01.08.2014 16:26]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [03.05.2010 19:45]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
818707BABCB3CAFA08C0A49EBB69DBA1 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
B938C1AE3ADCE166190895685B0BEB0D - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
09B4E13D25623D879D35286E2D29FF13 - C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
04AF8BC83A89D9B71F7E0BCAF9FDD768 - C:\Program Files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll - Adobe Acrobat
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01.08.2014 16:25]
avast Online Security - Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
==== Chromium Startpages ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Preferences
"startup_urls": [ "http://www.seznam.cz/" ]
==== Chromium Fix ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage-journal deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="C:\\ProgramData\\ICQ\\ICQNewTab\\newTab.html"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{213B6798-9435-4B6F-8AA9-728A976F8A04} Atlas hled nˇ Url="http://search.atlas.cz/?q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... 1I7GGLL_en"
{CDBFB47B-58A8-4111-BF95-06178DCE326D} GamingHarbor Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D} deleted successfully
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDBFB47B-58A8-4111-BF95-06178DCE326D} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C5096216-7703-409E-B85A-8A6EE7395128}}_is1 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\torchmediamoviestoolbar181FF deleted successfully
==== Empty IE Cache ======================
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Zdena\AppData\Local\Mozilla\Firefox\Profiles\tm736s2j.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=585 folders=48 58201664 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Zdena\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Zdena\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on po 22.09.2014 at 5:08:51,61 ======================
Tool run by Zdena on ne 21.09.2014 at 21:33:55,58.
Microsoft® Windows Vista™ Home Premium 6.0.6000 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Zdena\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
21.9.2014 21:38:35 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
user_pref("browser.search.defaultenginename", "Google");
Added to C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
user.js not found
---- Lines ask.com removed from prefs.js ----
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
---- Lines www.search removed from prefs.js ----
user_pref("browser.startup.homepage", "http://www.search.ask.com/?o=APN10648A& ... 84-326&t=4");
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- Lines a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292 removed from prefs.js ----
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.active", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.addressbar", "NA");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.addressbarenhanced", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb.was_copied", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb_dbWasSet", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb.was_copied", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.backgroundver", 1);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.certdomaininstaller", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallationTime.value", "%221402917792%2
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.description", ".");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.domain", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.enablesearch", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.homepage", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.changeprevious", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.iframe", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.InstallationThankYouPage", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.InstallationTime", 1402917792);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb._installer_additional_info.expiration
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb._installer_additional_info.value", "%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_appVer.value", "65");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_lastVersion.value", "0");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.lastDailyReport", "1403503716204");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.lastUpdate", "1403503694227");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.manifesturl", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.name", "Sense");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.newtab", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.opensearch", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.pluginsversion", 60);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.publisher", "Object Browser");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.searchstatus", 0);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.setnewtab", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.thankyou", "");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.updateinterval", 360);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.48292.ver", 65);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.apps", "48292");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.cid", 48292);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.firstrun", false);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.hadappinstalled", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.installationdate", 1403503704);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.installerAdditionalInfo", "{\"asw\":[131072, 8519685,
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.modetype", "production");
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.reportInstall", true);
user_pref("extensions.a143f44cfd99c4e458cd9ef929de77aa8bdbf60380097480c8d8efc48e28131a8com48292.statsDailyCounter", 1);
---- Lines a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510 removed from prefs.js ----
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.active", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.addressbar", "NA");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.addressbarenhanced", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb.was_copied", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb_dbWasSet", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb.was_copied", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.backgroundver", 1);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.certdomaininstaller", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallationTime.value", "%221402917792%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.uc.expiration", "Mon Jul 07 2014 08:08:45
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.cookie.uc.value", "%22%5C%22CZ%5C%22%22");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.description", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.domain", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.enablesearch", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.homepage", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.changeprevious", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.iframe", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.InstallationThankYouPage", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.InstallationTime", 1402917792);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb._installer_additional_info.expiration
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb._installer_additional_info.value", "%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_appVer.value", "310");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_lastVersion.value", "28");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_183015.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_196378.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353989.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353990.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_353991.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_376579.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_376579.value", "%2
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_483924.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_483925.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_534129.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.internaldb.Resources_resource_646958.expiration"
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.lastDailyReport", "1403503716093");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.lastUpdate", "1403503696315");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.manifesturl", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.name", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.newtab", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.opensearch", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.pluginsversion", 143);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.publisher", "iWebar");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.searchstatus", 0);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.setnewtab", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.thankyou", "");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.updateinterval", 360);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.35510.ver", 310);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.apps", "35510");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.cid", 35510);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.firstrun", false);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.hadappinstalled", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.installationdate", 1403503704);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.installerAdditionalInfo", "{\"asw\":[131072, 8519685,
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.modetype", "production");
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.reportInstall", true);
user_pref("extensions.a2eb528f3950d48a3be4b5d7de6c8331ea41e199b6ca44d23ab8773f2d1973314com35510.statsDailyCounter", 1);
---- Lines a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850 removed from prefs.js ----
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754ca
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754ca
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.active", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.addressbar", "NA");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.addressbarenhanced", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb.was_copied", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb_dbWasSet", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb.was_copied", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb_dbWasSet", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.backgroundver", 1);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.certdomaininstaller", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallationTime.value", "%221402917784%2
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.uc.expiration", "Mon Jul 07 2014 08:08:53
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.cookie.uc.value", "%22%5C%22CZ%5C%22%22");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.description", "Browser enhancer");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.domain", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.enablesearch", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.homepage", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.changeprevious", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.iframe", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.InstallationThankYouPage", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.InstallationTime", 1402917784);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.__defualt_browser__.value", "%22torch
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb._installer_additional_info.expiration
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb._installer_additional_info.value", "%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_appVer.value", "206");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_nextCheck.expiration", "Mon
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_remote_resources.expiration
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.lastDailyReport", "1403503730219");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.lastUpdate", "1403503716042");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.manifesturl", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.name", "Object Browser");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.newtab", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.opensearch", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.pluginsurl", "http://js.datagenserv.com/plugin/a
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.pluginsversion", 170);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.publisher", "Object Browser");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.searchstatus", 0);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.setnewtab", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.thankyou", "");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.updateinterval", 360);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.32850.ver", 206);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.apps", "32850");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.bic", "146c756f8f1813778d1500e7f3afeaf2");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.cid", 32850);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.firstrun", false);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.hadappinstalled", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.installationdate", 1403503704);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.installerAdditionalInfo", "{\"asw\":[131072, 131077, 0
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.modetype", "production");
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.reportInstall", true);
user_pref("extensions.a9321b2762c2e4c5fbd04b8118e512707c0c8a2d632754caca0b252e936311db9com32850.statsDailyCounter", 1);
---- Lines {0BA0192D-94A5-45e3-B2B8-3EC5A1A0B5EC} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{20a82645-c095-46ed-80e3-08825760534b}\":{\"descriptor\":\"C:\\\\
---- FireFox user.js and prefs.js backups ----
prefs_22.09.2014_0006_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D} deleted
C:\Program Files\GUT314D.tmp deleted
C:\Program Files\GUM312D.tmp deleted
C:\Users\Zdena\AppData\Roaming\ICQ Toolbar deleted
C:\PROGRA~2\spds90.txt deleted
C:\PROGRA~2\ICQ deleted
C:\PROGRA~2\ProductData deleted
C:\Users\Zdena\AppData\Local\CRE deleted
C:\Users\Zdena\AppData\Local\CrashRpt deleted
C:\Users\Public\MIsetup.exe deleted
C:\Users\Public\Documents\ShopperPro deleted
C:\Users\Zdena\Downloads\StartDownload (1).exe deleted
C:\Users\Zdena\Downloads\StartDownload (2).exe deleted
C:\Users\Zdena\Downloads\StartDownload.exe deleted
C:\Users\Zdena\AppData\LocalLow\torchmediamoviestoolbar181 deleted
C:\Windows\system32\Tasks\SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 deleted
C:\Users\Public\Documents\AlawarWrapper deleted
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\torchmediamoviestoolbar181 deleted
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [01.08.2014 16:26]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [03.05.2010 19:45]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
818707BABCB3CAFA08C0A49EBB69DBA1 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
B938C1AE3ADCE166190895685B0BEB0D - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
09B4E13D25623D879D35286E2D29FF13 - C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
04AF8BC83A89D9B71F7E0BCAF9FDD768 - C:\Program Files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll - Adobe Acrobat
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01.08.2014 16:25]
avast Online Security - Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
==== Chromium Startpages ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Preferences
"startup_urls": [ "http://www.seznam.cz/" ]
==== Chromium Fix ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cap1.conduit-apps.com_0.localstorage deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ciuvo.com_0.localstorage-journal deleted successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="C:\\ProgramData\\ICQ\\ICQNewTab\\newTab.html"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.seznam.cz/"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{213B6798-9435-4B6F-8AA9-728A976F8A04} Atlas hled nˇ Url="http://search.atlas.cz/?q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... 1I7GGLL_en"
{CDBFB47B-58A8-4111-BF95-06178DCE326D} GamingHarbor Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D} deleted successfully
HKEY_USERS\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CDBFB47B-58A8-4111-BF95-06178DCE326D} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C5096216-7703-409E-B85A-8A6EE7395128}}_is1 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\torchmediamoviestoolbar181FF deleted successfully
==== Empty IE Cache ======================
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\Zdena\AppData\Local\Mozilla\Firefox\Profiles\tm736s2j.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=585 folders=48 58201664 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Zdena\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Zdena\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Zdena\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
==== EOF on po 22.09.2014 at 5:08:51,61 ======================
Re: Prosím o kontrolu
Poprosim o novy log z FRST
-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
FRST.txt:
---------
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2014
Ran by Zdena (administrator) on ZDENA-NOTES on 22-09-2014 06:38:59
Running from C:\Users\Zdena\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
() C:\Program Files\Power Manager\PM.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(DivX, LLC) C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-11-22] (Microsoft Corporation)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4349952 2007-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [PowerManager] => C:\Program Files\Power Manager\PM.exe [29696 2007-03-13] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-08-01] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [T-Mobile Communication Centre] => C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [1355792 2011-03-08] (Gemfor s.r.o.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> c:\program files\movies app\datamngr\apcrtldr.dll <===== ATTENTION
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {213B6798-9435-4B6F-8AA9-728A976F8A04} URL = http://search.atlas.cz/?q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.7725.1624\swg.dll (Google Inc.)
BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-be ... canner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD44/JSCDL ... 586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-11-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-10]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-05-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-01]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR CustomProfile: C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-22]
CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-06-16]
CHR Extension: (Google Docs) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-09]
CHR Extension: (Google Drive) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-09]
CHR Extension: (YouTube) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-09]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-26]
CHR Extension: (Google Search) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-09]
CHR Extension: (Google Sheets) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-22]
CHR Extension: (avast! Online Security) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-01]
CHR Extension: (Google Wallet) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-09]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-01]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
R2 ameisvc; C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe [122608 2011-03-08] (Gemfor s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-01] (AVAST Software)
S2 gupdate1ca8ee972d573a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2010-01-06] (Google Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2006-07-20] () [File not signed]
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) [File not signed]
S2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [53328 2009-11-25] (ALWIL Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [23120 2009-11-25] (ALWIL Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-08-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [114768 2009-11-25] (ALWIL Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [48560 2009-11-25] (ALWIL Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-01] ()
R3 Cam5603D; C:\Windows\System32\Drivers\BisonCam.sys [753456 2007-05-16] ()
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2010-02-22] (MBB Incorporated)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2008-03-31] (Společnost Microsoft)
R3 SIS163u; C:\Windows\System32\DRIVERS\sis163u.sys [218624 2007-05-07] (Silicon Integrated Systems Corp.)
R3 smscirrx; C:\Windows\System32\DRIVERS\smscirrx.sys [40448 2007-02-02] (SMSC)
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R1 WINIO; C:\Windows\system32\WinIo.sys [9336 2007-01-04] (http://www.internals.com) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 SPDRIVER_1.37.0.193; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-22 00:35 - 2014-09-21 21:33 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:37 - 2014-09-22 05:08 - 00049201 _____ () C:\zoek-results.log
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:21 - 2014-09-22 00:21 - 00000000 ____D () C:\zoek_backup
2014-09-21 21:21 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:20 - 2014-09-21 21:21 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:17 - 2014-09-22 06:38 - 00001426 _____ () C:\Windows\setupact.log
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 15:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-09-21 15:54 - 2014-09-21 15:59 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:52 - 2014-09-21 15:51 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:41 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:46 - 2014-09-22 06:39 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:35 - 2014-09-22 06:39 - 00000000 ____D () C:\FRST
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\UC.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\RAR.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKUNZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\LHA.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\ARJ.PIF
2014-09-21 10:09 - 2014-09-21 10:10 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-22 06:39 - 2014-09-21 11:46 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-22 06:39 - 2014-09-21 10:35 - 00000000 ____D () C:\FRST
2014-09-22 06:38 - 2014-09-21 16:17 - 00001426 _____ () C:\Windows\setupact.log
2014-09-22 06:37 - 2008-02-23 09:17 - 01862552 _____ () C:\Windows\WindowsUpdate.log
2014-09-22 06:35 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.001
2014-09-22 06:34 - 2014-08-01 17:09 - 00056808 _____ () C:\Windows\PFRO.log
2014-09-22 06:34 - 2010-01-06 18:10 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-22 06:34 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-22 06:34 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-22 06:34 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-22 05:25 - 2007-11-22 08:02 - 00003308 _____ () C:\Windows\bthservsdp.dat
2014-09-22 05:25 - 2006-11-02 15:01 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-22 05:14 - 2010-01-06 18:10 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-22 05:08 - 2014-09-21 21:37 - 00049201 _____ () C:\zoek-results.log
2014-09-22 02:58 - 2013-03-25 18:31 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-22 00:21 - 2014-09-21 21:21 - 00000000 ____D () C:\zoek_backup
2014-09-22 00:09 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public
2014-09-21 21:33 - 2014-09-22 00:35 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:33 - 2008-02-23 16:09 - 00036352 _____ () C:\Users\Zdena\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:26 - 2014-09-21 21:21 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:21 - 2014-09-21 21:20 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:19 - 2006-11-02 12:33 - 01259320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 16:13 - 2008-02-23 09:22 - 00072224 _____ () C:\Users\Zdena\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-21 16:12 - 2006-11-02 14:47 - 00312888 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-21 15:59 - 2014-09-21 15:54 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:51 - 2014-09-21 15:52 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:39 - 2014-09-21 14:41 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:28 - 2007-11-22 09:15 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-09-21 10:52 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2014-09-21 10:52 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-21 10:51 - 2007-11-22 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:31 - 2014-09-21 10:30 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:31 - 2008-02-23 09:21 - 00000000 ____D () C:\Users\Zdena
2014-09-21 10:23 - 2014-09-21 10:22 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-07-18 09:58 - 00000000 ____D () C:\Program Files (x86)
2014-09-21 10:10 - 2014-09-21 10:09 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-21 10:07 - 2008-02-23 15:33 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job
2014-09-14 20:39 - 2013-08-13 15:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 20:23 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-09 22:29 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.dat
2014-09-09 22:27 - 2008-02-23 09:54 - 00051815 _____ () C:\Windows\KernelMessage
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-25 06:53 - 2009-10-03 15:34 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-22 05:13
==================== End Of Log ============================
Addition.txt:
------------
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-09-2014
Ran by Zdena at 2014-09-22 06:40:00
Running from C:\Users\Zdena\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKCU\...\uTorrent) (Version: 1.7.7 - )
µTorrent CZ 1.7.7 (build 8179) (HKLM\...\µTorrent CZ_is1) (Version: - emc)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7 Wonders of the Ancient World (HKLM\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111170320}) (Version: - Oberon Media)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) (Version: 8.1.2 - Adobe Systems, Inc) Hidden
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader 8 - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-A81200000003}) (Version: 8.1.2 - Adobe Systems Incorporated)
Adobe Reader 8.1.2 Security Update 1 (KB403742) (HKLM\...\{AC76BA86-7AD7-1029-7B44-A81200000003}_Adobe Reader 8 - Czech) (Version: - )
Advanced SystemCare 7 (HKLM\...\Advanced SystemCare 7_is1) (Version: 7.2.1 - IObit)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - )
Around the World in 80 Days (HKLM\...\Around the World in 80 Days) (Version: - Alawar Entertainment Inc.)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software)
Big Fish Games Client (HKLM\...\BFGC) (Version: 1.3.0.6 - )
Bison WebCam (HKLM\...\{4A57592C-FF92-4083-97A9-92783BD5AFB4}) (Version: - )
BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden
Codec Pack - All In 1 6.0.0.0 (HKLM\...\Cool's_Codec_pack_4.12) (Version: - )
Copy (Version: 130.0.366.000 - Hewlett-Packard) Hidden
Cradle of Rome (HKLM\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11219217}) (Version: - Oberon Media)
Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden
DJ_AIO_06_F2400_SW_Min (Version: 130.0.373.000 - Hewlett-Packard) Hidden
F2400 (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Farm Frenzy 2 (HKLM\...\Farm Frenzy 2) (Version: - Alawar Entertainment Inc.)
FirstSteps Diagnostics (HKLM\...\{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}) (Version: 1.00 - Fujitsu Siemens Computers)
Fujitsu Siemens Computers WLAN 802.11b/g (SiS163u) (HKLM\...\SiS163u) (Version: - )
GamingHarbor Toolbar (HKLM\...\GamingHarbor Toolbar) (Version: - DoubleD)
GamingHarbor Toolbar (Version: 4.2.3.22530 - DoubleD Advertising Limited) Hidden
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Chrome (HKLM\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F10001) (Version: 7.65.00.00 - Conexant)
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
HPPhotoGadget (Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden
ICQ6.5 (HKLM\...\{60DE4033-9503-48D1-A483-7846BD217CA9}) (Version: 6.5 - ICQ)
InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B6.193 - InterVideo Inc.)
InterVideo WinDVD 8 (Version: 8.0-B6.193 - InterVideo Inc.) Hidden
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 3.1.8.2434 - IObit)
Java(TM) 6 Update 7 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.)
MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Media Access Startup (HKLM\...\{16B6279B-9FF5-41fb-8BF9-404324F5DD1F}}_is1) (Version: - )
Microsoft .NET Framework 3.5 Language Pack SP1 - csy (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\...\{C73B5B3B-F974-48CA-8B91-3E8A432AEA5B}) (Version: 08.05.0822 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 cs) (HKLM\...\Mozilla Firefox 26.0 (x86 cs)) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Multi-Instrument version 3.1 (HKLM\...\Multi-Instrument 3.1_is1) (Version: 3.1 - Virtins Technology)
Nero 7 Essentials (HKLM\...\{81CD6232-10F5-4832-B3DA-1B88B1571029}) (Version: 7.02.5851 - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
OpenOffice.org Installer 1.0 (HKLM\...\{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}) (Version: 1.0.9221 - Sun Microsystems)
Pexeso 1.4 (HKLM\...\Pexeso_is1) (Version: - Galerie GIF ikon)
PokerRoom Home Game Organizer (HKLM\...\PokerRoom Home Game Organizer) (Version: - )
PokerStars (HKLM\...\PokerStars) (Version: - PokerStars)
Power Manager 2.1.7 (HKLM\...\Power Manager_is1) (Version: 2.1.7 - FIC, Inc.)
PowerDV (HKLM\...\{B804C424-B66D-447A-84BD-C6B88C392C3A}) (Version: 2.0.1812 - CyberLink Corporation)
Příšerky, s.r.o., Strašidelný ostrov (HKLM\...\{69F524B9-B18B-4FFD-8515-418586483CB4}) (Version: - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - )
Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype web features (HKLM\...\{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}) (Version: 1.0.3971 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Surfing Protection (HKLM\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.51a - Ghisler Software GmbH)
TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 0.9.8a (HKLM\...\VLC media player) (Version: 0.9.8a - VideoLAN Team)
Web'n'walk Manager (HKLM\...\T-Mobile Communication Centre) (Version: 2011-03-08 - Gemfor s.r.o.)
WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden
ZTE Drivers (HKLM\...\{ACC9984D-E78B-4fcd-BE44-4E3F186DDA33}) (Version: 1.2059.0.12 - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{66E8DCC7-97D2-4A89-8E08-D0610FF0878C}\InprocServer32 -> C:\Users\Zdena\AppData\Local\Conduit\Community Alerts\Alert.dll No File
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\localserver32 -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
==================== Restore Points =========================
02-09-2014 16:50:13 Windows Update
06-09-2014 21:35:19 Windows Update
09-09-2014 17:59:15 Windows Update
13-09-2014 05:39:33 Windows Update
14-09-2014 18:19:11 Windows Update
16-09-2014 17:14:41 Windows Update
19-09-2014 18:21:04 Windows Update
21-09-2014 08:45:18 Odebráno: Microsoft Office Professional Edition 2003
21-09-2014 09:26:20 Odebráno: Microsoft Office File Validation Add-In
21-09-2014 19:38:08 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 12:23 - 2014-09-21 21:39 - 00000781 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0A0E9B54-FD70-4FFD-86C3-EA83ECA1DA82} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-02-13] (IObit)
Task: {0C3AF200-FADC-49E5-880E-DEE192C8B79A} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2006-11-02] (Společnost Microsoft)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {1CECB1E9-48A3-4C7A-B7C9-3F409BA733C0} - System32\Tasks\{DDDEC95C-ADF3-4115-98A7-8347F793A55A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2006-11-02] (Microsoft Corporation)
Task: {852FFD5C-B1E2-4016-B5D5-DDCB12AEDC5E} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe [2014-02-11] (IObit)
Task: {88BBE563-2724-4141-8C61-98E9C0AF440D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-06] (Google Inc.)
Task: {9EB44560-63F6-4CA3-8294-048D3F7D340B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {A4B11CBA-E4B0-4AF1-9A5B-E7F7F3DB4100} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-06] (Google Inc.)
Task: {A9444EA8-C79D-4573-A915-4473165D9652} - \SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {C2CE6203-E44F-4AF9-93F2-B4F7863CA617} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: {C8F217BC-B50E-49DC-91AB-610E688FDD93} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-01] (AVAST Software)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2006-11-02] ()
Task: {F0283197-BE2A-44B5-AD54-C92063E0F6B2} - System32\Tasks\ASC7_SkipUac_Zdena => C:\Program Files\IObit\Advanced SystemCare 7\ASC.exe [2014-03-10] (IObit)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) =============
2014-08-01 15:56 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files\IObit\Advanced SystemCare 7\sqlite3.dll
2014-08-01 16:25 - 2014-08-01 16:25 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-09-21 20:17 - 2014-09-21 20:17 - 02864640 _____ () C:\Program Files\AVAST Software\Avast\defs\14092101\algo.dll
2007-11-22 09:04 - 2007-03-13 16:01 - 00029696 _____ () C:\Program Files\Power Manager\PM.exe
2007-11-22 09:21 - 2006-07-20 02:36 - 00262247 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2013-08-21 11:19 - 2013-08-21 11:19 - 01392640 _____ () C:\Program Files\DivX\DivX Media Server\DivXDLNATranscoder.dll
2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2014-08-01 16:25 - 2014-08-01 16:25 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-01 15:56 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files\IObit\Advanced SystemCare 7\webres.dll
2014-08-01 15:56 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madExcept_.bpl
2014-08-01 15:56 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madBasic_.bpl
2014-08-01 15:56 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madDisAsm_.bpl
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/22/2014 06:35:21 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
Error: (09/22/2014 05:10:51 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
Error: (09/21/2014 04:19:42 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: Cílový soubor pro platformu Windows Feedback Platform (soubor DLL obsahující seznam problémů v tomto počítači, které vyžadují další sběr dat pro diagnostiku) nelze analyzovat. Kód chyby je 8014FFF9.
Error: (09/21/2014 04:14:32 PM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
System errors:
=============
Error: (09/22/2014 06:36:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: SPDRIVER_1.37.0.193%%3
Error: (09/22/2014 06:36:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Datamngr Coordinator2%%2
Error: (09/22/2014 05:07:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: SPDRIVER_1.37.0.193%%3
Error: (09/22/2014 05:07:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Datamngr Coordinator2%%2
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 3 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 4 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 2 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 00:06:19 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (09/22/2014 00:06:15 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (09/22/2014 00:06:11 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Microsoft Office Sessions:
=========================
Error: (09/22/2014 06:35:21 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
Error: (09/22/2014 05:10:51 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
Error: (09/21/2014 04:19:42 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: 8014FFF9
Error: (09/21/2014 04:14:32 PM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
CodeIntegrity Errors:
===================================
Date: 2014-09-21 11:47:39.289
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:39.180
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:39.070
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:38.946
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:36.013
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.904
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.794
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.670
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 10:37:34.615
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 10:37:34.496
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Processor model unknown
Percentage of memory in use: 39%
Total physical RAM: 2046.38 MB
Available physical RAM: 1240.63 MB
Total Pagefile: 4309.84 MB
Available Pagefile: 3368.58 MB
Total Virtual: 2047.88 MB
Available Virtual: 1932.44 MB
==================== Drives ================================
Drive c: (SYSTEM) (Fixed) (Total:92.21 GB) (Free:50.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (000000) (Fixed) (Total:149.05 GB) (Free:148.94 GB) NTFS
Drive e: (DATA) (Fixed) (Total:45.12 GB) (Free:44.85 GB) NTFS
Drive g: () (Removable) (Total:7.46 GB) (Free:5.9 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: 621E1C62)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
Partition 2: (Active) - (Size=92.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=45.1 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: F4542371)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 7.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================
---------
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2014
Ran by Zdena (administrator) on ZDENA-NOTES on 22-09-2014 06:38:59
Running from C:\Users\Zdena\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 7
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
() C:\Program Files\Power Manager\PM.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(DivX, LLC) C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Fujitsu Siemens Computers) C:\FirstSteps\OnlineDiagnostic\TestManager\TestHandler.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Gemfor s.r.o.) C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1006264 2007-11-22] (Microsoft Corporation)
HKLM\...\Run: [NvSvc] => RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4349952 2007-01-18] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [159744 2006-11-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [PowerManager] => C:\Program Files\Power Manager\PM.exe [29696 2007-03-13] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-08-01] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [T-Mobile Communication Centre] => C:\Program Files\T-Mobile\Web'n'walk Manager\Manager.exe [1355792 2011-03-08] (Gemfor s.r.o.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> c:\program files\movies app\datamngr\apcrtldr.dll <===== ATTENTION
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {213B6798-9435-4B6F-8AA9-728A976F8A04} URL = http://search.atlas.cz/?q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Podpora odkazu pro Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
BHO: SSVHelper Class -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.7725.1624\swg.dll (Google Inc.)
BHO: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-be ... canner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.sun.com/s/ESD44/JSCDL ... 586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 04 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1 192.168.3.1
FireFox:
========
FF ProfilePath: C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A&gct=hp& ... 84-326&t=4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-11-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-10]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-05-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-01]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR CustomProfile: C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-22]
CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2014-06-16]
CHR Extension: (Google Docs) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-09]
CHR Extension: (Google Drive) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-06-09]
CHR Extension: (YouTube) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-06-09]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-26]
CHR Extension: (Google Search) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-06-09]
CHR Extension: (Google Sheets) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-22]
CHR Extension: (avast! Online Security) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-01]
CHR Extension: (Google Wallet) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Users\Zdena\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-06-09]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-01]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
R2 ameisvc; C:\Program Files\T-Mobile\Web'n'walk Manager\ameisvc.exe [122608 2011-03-08] (Gemfor s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-01] (AVAST Software)
S2 gupdate1ca8ee972d573a0; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2010-01-06] (Google Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [262247 2006-07-20] () [File not signed]
R2 TestHandler; C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [204800 2006-12-08] (Fujitsu Siemens Computers) [File not signed]
S2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-08-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [53328 2009-11-25] (ALWIL Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [23120 2009-11-25] (ALWIL Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-08-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-08-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [114768 2009-11-25] (ALWIL Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [48560 2009-11-25] (ALWIL Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-08-01] ()
R3 Cam5603D; C:\Windows\System32\Drivers\BisonCam.sys [753456 2007-05-16] ()
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [183912 2006-11-02] (Společnost Microsoft)
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48256 2007-06-13] (JMicron Technology Corp.)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2010-02-22] (MBB Incorporated)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1060920 2008-03-31] (Společnost Microsoft)
R3 SIS163u; C:\Windows\System32\DRIVERS\sis163u.sys [218624 2007-05-07] (Silicon Integrated Systems Corp.)
R3 smscirrx; C:\Windows\System32\DRIVERS\smscirrx.sys [40448 2007-02-02] (SMSC)
S4 viamraid; C:\Windows\system32\drivers\viamraid.sys [102912 2006-11-08] (VIA Technologies inc,.ltd)
R1 WINIO; C:\Windows\system32\WinIo.sys [9336 2007-01-04] (http://www.internals.com) [File not signed]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 SPDRIVER_1.37.0.193; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-22 00:35 - 2014-09-21 21:33 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:37 - 2014-09-22 05:08 - 00049201 _____ () C:\zoek-results.log
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:21 - 2014-09-22 00:21 - 00000000 ____D () C:\zoek_backup
2014-09-21 21:21 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:20 - 2014-09-21 21:21 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:17 - 2014-09-22 06:38 - 00001426 _____ () C:\Windows\setupact.log
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 15:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-09-21 15:54 - 2014-09-21 15:59 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:52 - 2014-09-21 15:51 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:41 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:46 - 2014-09-22 06:39 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:35 - 2014-09-22 06:39 - 00000000 ____D () C:\FRST
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\UC.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\RAR.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\PKUNZIP.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\LHA.PIF
2014-09-21 10:11 - 2014-04-30 08:51 - 00000545 _____ () C:\Windows\ARJ.PIF
2014-09-21 10:09 - 2014-09-21 10:10 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-22 06:39 - 2014-09-21 11:46 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-22 06:39 - 2014-09-21 10:35 - 00000000 ____D () C:\FRST
2014-09-22 06:38 - 2014-09-21 16:17 - 00001426 _____ () C:\Windows\setupact.log
2014-09-22 06:37 - 2008-02-23 09:17 - 01862552 _____ () C:\Windows\WindowsUpdate.log
2014-09-22 06:35 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.001
2014-09-22 06:34 - 2014-08-01 17:09 - 00056808 _____ () C:\Windows\PFRO.log
2014-09-22 06:34 - 2010-01-06 18:10 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-22 06:34 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-22 06:34 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-22 06:34 - 2006-11-02 14:47 - 00003072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-22 05:25 - 2007-11-22 08:02 - 00003308 _____ () C:\Windows\bthservsdp.dat
2014-09-22 05:25 - 2006-11-02 15:01 - 00032604 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-22 05:14 - 2010-01-06 18:10 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-22 05:08 - 2014-09-21 21:37 - 00049201 _____ () C:\zoek-results.log
2014-09-22 02:58 - 2013-03-25 18:31 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-22 00:21 - 2014-09-21 21:21 - 00000000 ____D () C:\zoek_backup
2014-09-22 00:09 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public
2014-09-21 21:33 - 2014-09-22 00:35 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:33 - 2008-02-23 16:09 - 00036352 _____ () C:\Users\Zdena\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:26 - 2014-09-21 21:21 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:21 - 2014-09-21 21:20 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:19 - 2006-11-02 12:33 - 01259320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 16:13 - 2008-02-23 09:22 - 00072224 _____ () C:\Users\Zdena\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-21 16:12 - 2006-11-02 14:47 - 00312888 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-21 15:59 - 2014-09-21 15:54 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:51 - 2014-09-21 15:52 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:39 - 2014-09-21 14:41 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:28 - 2007-11-22 09:15 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-09-21 10:52 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2014-09-21 10:52 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-09-21 10:51 - 2007-11-22 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Desktop\FRST.exe
2014-09-21 10:31 - 2014-09-21 10:30 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:31 - 2008-02-23 09:21 - 00000000 ____D () C:\Users\Zdena
2014-09-21 10:23 - 2014-09-21 10:22 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
2014-09-21 10:11 - 2014-09-21 10:11 - 00000794 _____ () C:\Users\Public\Desktop\Total Commander.lnk
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Zdena\AppData\Roaming\GHISLER
2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Total Commander
2014-09-21 10:11 - 2014-07-18 09:58 - 00000000 ____D () C:\Program Files (x86)
2014-09-21 10:10 - 2014-09-21 10:09 - 03721616 _____ (Ghisler Software GmbH) C:\Users\Zdena\Downloads\tcm851ax32.exe
2014-09-21 10:07 - 2008-02-23 15:33 - 00000418 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job
2014-09-14 20:39 - 2013-08-13 15:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 20:23 - 2006-11-02 12:24 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-09-09 23:58 - 2014-09-09 23:58 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-09 23:58 - 2013-03-25 18:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-09 22:29 - 2008-02-23 15:30 - 00027335 _____ () C:\Users\Zdena\AppData\Roaming\nvModes.dat
2014-09-09 22:27 - 2008-02-23 09:54 - 00051815 _____ () C:\Windows\KernelMessage
2014-08-25 19:05 - 2014-08-25 19:05 - 00089681 _____ () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk.htm
2014-08-25 19:05 - 2014-08-25 19:05 - 00000000 ____D () C:\Users\Zdena\Desktop\Online kalkulačka s páskou - Kalkulacka.sk_files
2014-08-25 06:53 - 2009-10-03 15:34 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-24 20:18 - 2014-08-24 20:18 - 00129148 _____ () C:\Users\Zdena\Desktop\Domovská stránka reff.cz.htm
2014-08-24 20:18 - 2014-08-24 20:18 - 00000000 ____D () C:\Users\Zdena\Desktop\Domovská stránka reff.cz_files
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-22 05:13
==================== End Of Log ============================
Addition.txt:
------------
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-09-2014
Ran by Zdena at 2014-09-22 06:40:00
Running from C:\Users\Zdena\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKCU\...\uTorrent) (Version: 1.7.7 - )
µTorrent CZ 1.7.7 (build 8179) (HKLM\...\µTorrent CZ_is1) (Version: - emc)
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
7 Wonders of the Ancient World (HKLM\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111170320}) (Version: - Oberon Media)
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) (Version: 8.1.2 - Adobe Systems, Inc) Hidden
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader 8 - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-A81200000003}) (Version: 8.1.2 - Adobe Systems Incorporated)
Adobe Reader 8.1.2 Security Update 1 (KB403742) (HKLM\...\{AC76BA86-7AD7-1029-7B44-A81200000003}_Adobe Reader 8 - Czech) (Version: - )
Advanced SystemCare 7 (HKLM\...\Advanced SystemCare 7_is1) (Version: 7.2.1 - IObit)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - )
Around the World in 80 Days (HKLM\...\Around the World in 80 Days) (Version: - Alawar Entertainment Inc.)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software)
Big Fish Games Client (HKLM\...\BFGC) (Version: 1.3.0.6 - )
Bison WebCam (HKLM\...\{4A57592C-FF92-4083-97A9-92783BD5AFB4}) (Version: - )
BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden
Codec Pack - All In 1 6.0.0.0 (HKLM\...\Cool's_Codec_pack_4.12) (Version: - )
Copy (Version: 130.0.366.000 - Hewlett-Packard) Hidden
Cradle of Rome (HKLM\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11219217}) (Version: - Oberon Media)
Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden
DJ_AIO_06_F2400_SW_Min (Version: 130.0.373.000 - Hewlett-Packard) Hidden
F2400 (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Farm Frenzy 2 (HKLM\...\Farm Frenzy 2) (Version: - Alawar Entertainment Inc.)
FirstSteps Diagnostics (HKLM\...\{94D66D71-12F0-48A5-B46A-D4B835A0F1B7}) (Version: 1.00 - Fujitsu Siemens Computers)
Fujitsu Siemens Computers WLAN 802.11b/g (SiS163u) (HKLM\...\SiS163u) (Version: - )
GamingHarbor Toolbar (HKLM\...\GamingHarbor Toolbar) (Version: - DoubleD)
GamingHarbor Toolbar (Version: 4.2.3.22530 - DoubleD Advertising Limited) Hidden
Google Earth Plug-in (HKLM\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Chrome (HKLM\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F10001) (Version: 7.65.00.00 - Conexant)
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
HPPhotoGadget (Version: 130.0.282.000 - Hewlett-Packard) Hidden
hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden
ICQ6.5 (HKLM\...\{60DE4033-9503-48D1-A483-7846BD217CA9}) (Version: 6.5 - ICQ)
InterVideo WinDVD 8 (HKLM\...\InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}) (Version: 8.0-B6.193 - InterVideo Inc.)
InterVideo WinDVD 8 (Version: 8.0-B6.193 - InterVideo Inc.) Hidden
IObit Uninstaller (HKLM\...\IObitUninstall) (Version: 3.1.8.2434 - IObit)
Java(TM) 6 Update 7 (HKLM\...\{3248F0A8-6813-11D6-A77B-00B0D0160070}) (Version: 1.6.0.70 - Sun Microsystems, Inc.)
MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Media Access Startup (HKLM\...\{16B6279B-9FF5-41fb-8BF9-404324F5DD1F}}_is1) (Version: - )
Microsoft .NET Framework 3.5 Language Pack SP1 - csy (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - csy) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (HKLM\...\{C73B5B3B-F974-48CA-8B91-3E8A432AEA5B}) (Version: 08.05.0822 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 cs) (HKLM\...\Mozilla Firefox 26.0 (x86 cs)) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Multi-Instrument version 3.1 (HKLM\...\Multi-Instrument 3.1_is1) (Version: 3.1 - Virtins Technology)
Nero 7 Essentials (HKLM\...\{81CD6232-10F5-4832-B3DA-1B88B1571029}) (Version: 7.02.5851 - Nero AG)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
OpenOffice.org Installer 1.0 (HKLM\...\{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}) (Version: 1.0.9221 - Sun Microsystems)
Pexeso 1.4 (HKLM\...\Pexeso_is1) (Version: - Galerie GIF ikon)
PokerRoom Home Game Organizer (HKLM\...\PokerRoom Home Game Organizer) (Version: - )
PokerStars (HKLM\...\PokerStars) (Version: - PokerStars)
Power Manager 2.1.7 (HKLM\...\Power Manager_is1) (Version: 2.1.7 - FIC, Inc.)
PowerDV (HKLM\...\{B804C424-B66D-447A-84BD-C6B88C392C3A}) (Version: 2.0.1812 - CyberLink Corporation)
Příšerky, s.r.o., Strašidelný ostrov (HKLM\...\{69F524B9-B18B-4FFD-8515-418586483CB4}) (Version: - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - )
Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype web features (HKLM\...\{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}) (Version: 1.0.3971 - Skype Technologies S.A.)
Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Surfing Protection (HKLM\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.51a - Ghisler Software GmbH)
TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 0.9.8a (HKLM\...\VLC media player) (Version: 0.9.8a - VideoLAN Team)
Web'n'walk Manager (HKLM\...\T-Mobile Communication Centre) (Version: 2011-03-08 - Gemfor s.r.o.)
WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden
ZTE Drivers (HKLM\...\{ACC9984D-E78B-4fcd-BE44-4E3F186DDA33}) (Version: 1.2059.0.12 - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Zdena\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{66E8DCC7-97D2-4A89-8E08-D0610FF0878C}\InprocServer32 -> C:\Users\Zdena\AppData\Local\Conduit\Community Alerts\Alert.dll No File
CustomCLSID: HKU\S-1-5-21-54195102-1349951187-670571874-1000_Classes\CLSID\{9E385F0A-0BA2-430C-96AA-4399C5E40F6C}\localserver32 -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
==================== Restore Points =========================
02-09-2014 16:50:13 Windows Update
06-09-2014 21:35:19 Windows Update
09-09-2014 17:59:15 Windows Update
13-09-2014 05:39:33 Windows Update
14-09-2014 18:19:11 Windows Update
16-09-2014 17:14:41 Windows Update
19-09-2014 18:21:04 Windows Update
21-09-2014 08:45:18 Odebráno: Microsoft Office Professional Edition 2003
21-09-2014 09:26:20 Odebráno: Microsoft Office File Validation Add-In
21-09-2014 19:38:08 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 12:23 - 2014-09-21 21:39 - 00000781 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0A0E9B54-FD70-4FFD-86C3-EA83ECA1DA82} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-02-13] (IObit)
Task: {0C3AF200-FADC-49E5-880E-DEE192C8B79A} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\system32\RAServer.exe [2006-11-02] (Společnost Microsoft)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {1CECB1E9-48A3-4C7A-B7C9-3F409BA733C0} - System32\Tasks\{DDDEC95C-ADF3-4115-98A7-8347F793A55A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2006-11-02] (Microsoft Corporation)
Task: {852FFD5C-B1E2-4016-B5D5-DDCB12AEDC5E} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 7\Monitor.exe [2014-02-11] (IObit)
Task: {88BBE563-2724-4141-8C61-98E9C0AF440D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-06] (Google Inc.)
Task: {9EB44560-63F6-4CA3-8294-048D3F7D340B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {A4B11CBA-E4B0-4AF1-9A5B-E7F7F3DB4100} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-06] (Google Inc.)
Task: {A9444EA8-C79D-4573-A915-4473165D9652} - \SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {C2CE6203-E44F-4AF9-93F2-B4F7863CA617} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: {C8F217BC-B50E-49DC-91AB-610E688FDD93} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-01] (AVAST Software)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2006-11-02] ()
Task: {F0283197-BE2A-44B5-AD54-C92063E0F6B2} - System32\Tasks\ASC7_SkipUac_Zdena => C:\Program Files\IObit\Advanced SystemCare 7\ASC.exe [2014-03-10] (IObit)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{AB18F02A-D20D-49DF-9DB8-D65624159D7C}.job => C:\Windows\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) =============
2014-08-01 15:56 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files\IObit\Advanced SystemCare 7\sqlite3.dll
2014-08-01 16:25 - 2014-08-01 16:25 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-09-21 20:17 - 2014-09-21 20:17 - 02864640 _____ () C:\Program Files\AVAST Software\Avast\defs\14092101\algo.dll
2007-11-22 09:04 - 2007-03-13 16:01 - 00029696 _____ () C:\Program Files\Power Manager\PM.exe
2007-11-22 09:21 - 2006-07-20 02:36 - 00262247 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2013-08-21 11:19 - 2013-08-21 11:19 - 01392640 _____ () C:\Program Files\DivX\DivX Media Server\DivXDLNATranscoder.dll
2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2014-08-01 16:25 - 2014-08-01 16:25 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-01 15:56 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files\IObit\Advanced SystemCare 7\webres.dll
2014-08-01 15:56 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madExcept_.bpl
2014-08-01 15:56 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madBasic_.bpl
2014-08-01 15:56 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files\IObit\Advanced SystemCare 7\madDisAsm_.bpl
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
==================== Faulty Device Manager Devices =============
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: 6TO4 Adapter
Description: Microsoft 6to4 Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: isatap.{53166294-C176-45A9-B495-BD163AF926E7}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/22/2014 06:35:21 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
Error: (09/22/2014 05:10:51 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
Error: (09/21/2014 04:19:42 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: Cílový soubor pro platformu Windows Feedback Platform (soubor DLL obsahující seznam problémů v tomto počítači, které vyžadují další sběr dat pro diagnostiku) nelze analyzovat. Kód chyby je 8014FFF9.
Error: (09/21/2014 04:14:32 PM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: Kontrolní bod ochrany v reálném čase programu %Zdena-notes27 zjistil chybu a nepodařilo se jej spustit.
Uživatel: Zdena-notes\Zdena
Kontrolní bod: 57
Kód chyby: 0x80070005
Popis chyby: Přístup byl odepřen.
System errors:
=============
Error: (09/22/2014 06:36:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: SPDRIVER_1.37.0.193%%3
Error: (09/22/2014 06:36:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Datamngr Coordinator2%%2
Error: (09/22/2014 05:07:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: SPDRIVER_1.37.0.193%%3
Error: (09/22/2014 05:07:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Datamngr Coordinator2%%2
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 3 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 4 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 05:05:37 AM) (Source: ACPI) (EventID: 6) (User: )
Description: IRQARB: Systém ACPI BIOS neobsahuje přerušení IRQ pro zařízení v patici PCI 2 s funkcí 0.
Obraťte se na prodejce systému s žádostí o odbornou pomoc.
Error: (09/22/2014 00:06:19 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (09/22/2014 00:06:15 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Error: (09/22/2014 00:06:11 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: PEVSystemStart
Microsoft Office Sessions:
=========================
Error: (09/22/2014 06:35:21 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
Error: (09/22/2014 05:10:51 AM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
Error: (09/21/2014 04:19:42 PM) (Source: WerSvc) (EventID: 5007) (User: )
Description: 8014FFF9
Error: (09/21/2014 04:14:32 PM) (Source: WinDefendRtp) (EventID: 3003) (User: )
Description: %%8271.1.1505.0570x80070005Přístup byl odepřen. Zdena-notesZdenaS-1-5-21-54195102-1349951187-670571874-1000
CodeIntegrity Errors:
===================================
Date: 2014-09-21 11:47:39.289
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:39.180
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:39.070
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:38.946
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:36.013
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.904
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.794
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 11:47:35.670
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSP.sys because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 10:37:34.615
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
Date: 2014-09-21 10:37:34.496
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Movies App\Datamngr\setmgrc2.cfg because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: AMD Processor model unknown
Percentage of memory in use: 39%
Total physical RAM: 2046.38 MB
Available physical RAM: 1240.63 MB
Total Pagefile: 4309.84 MB
Available Pagefile: 3368.58 MB
Total Virtual: 2047.88 MB
Available Virtual: 1932.44 MB
==================== Drives ================================
Drive c: (SYSTEM) (Fixed) (Total:92.21 GB) (Free:50.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (000000) (Fixed) (Total:149.05 GB) (Free:148.94 GB) NTFS
Drive e: (DATA) (Fixed) (Total:45.12 GB) (Free:44.85 GB) NTFS
Drive g: () (Removable) (Total:7.46 GB) (Free:5.9 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: 621E1C62)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
Partition 2: (Active) - (Size=92.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=45.1 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: F4542371)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 7.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================
Re: Prosím o kontrolu


- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG) HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] () HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.) HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit) HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION HKLM\...\AppCertDlls: [x86] -> c:\program files\movies app\datamngr\apcrtldr.dll <===== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit) BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) FF Homepage: hxxp://www.search.ask.com/?o=APN10648A& ... 84-326&t=4 FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [Not Found] FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [Not Found] FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [Not Found] FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [Not Found] FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found] FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found] R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit) S2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [X] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X] S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S2 SPDRIVER_1.37.0.193; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [X] c:\RecInfo C:\Program Files\ShopperPro c:\program files\movies app C:\Program Files\IObit 2014-09-22 00:35 - 2014-09-21 21:33 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-09-21 21:37 - 2014-09-22 05:08 - 00049201 _____ () C:\zoek-results.log 2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe 2014-09-21 21:21 - 2014-09-22 00:21 - 00000000 ____D () C:\zoek_backup 2014-09-21 21:21 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe 2014-09-21 21:20 - 2014-09-21 21:21 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip 2014-09-21 16:17 - 2014-09-22 06:38 - 00001426 _____ () C:\Windows\setupact.log 2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-09-21 15:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-09-21 15:54 - 2014-09-21 15:59 - 00000000 ____D () C:\AdwCleaner 2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe 2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe 2014-09-21 15:52 - 2014-09-21 15:51 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt 2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT 2014-09-21 14:41 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe 2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe 2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt 2014-09-21 11:46 - 2014-09-22 06:39 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt 2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe 2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe 2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe Task: {A9444EA8-C79D-4573-A915-4473165D9652} - \SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 No Task File <==== ATTENTION AlternateDataStreams: C:\ProgramData\TEMP:0E660858 AlternateDataStreams: C:\ProgramData\TEMP:561568A4 AlternateDataStreams: C:\ProgramData\TEMP:9C68C476 AlternateDataStreams: C:\ProgramData\TEMP:BB24555F AlternateDataStreams: C:\ProgramData\TEMP:DF695222 AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty Hosts: EmptyTemp: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 21-09-2014
Ran by Zdena at 2014-09-22 22:57:34 Run:1
Running from C:\Users\Zdena\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> c:\program files\movies app\datamngr\apcrtldr.dll <===== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A& ... 84-326&t=4
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
S2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 SPDRIVER_1.37.0.193; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [X]
c:\RecInfo
C:\Program Files\ShopperPro
c:\program files\movies app
C:\Program Files\IObit
2014-09-22 00:35 - 2014-09-21 21:33 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:37 - 2014-09-22 05:08 - 00049201 _____ () C:\zoek-results.log
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:21 - 2014-09-22 00:21 - 00000000 ____D () C:\zoek_backup
2014-09-21 21:21 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:20 - 2014-09-21 21:21 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:17 - 2014-09-22 06:38 - 00001426 _____ () C:\Windows\setupact.log
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 15:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-09-21 15:54 - 2014-09-21 15:59 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:52 - 2014-09-21 15:51 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:41 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:46 - 2014-09-22 06:39 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
Task: {A9444EA8-C79D-4573-A915-4473165D9652} - \SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 No Task File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\recinfo435 => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" => Value not found.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => Value not found.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x86 => value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully.
HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
Default URLSearchHook was restored successfully .
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully.
"HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}" => Key deleted successfully.
"HKCR\CLSID\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}" => Key deleted successfully.
Firefox homepage deleted successfully.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com => not found.
AdvancedSystemCareService7 => Service not found.
DatamngrCoordinator2 => Service deleted successfully.
blbdrive => Service deleted successfully.
cpuz133 => Service deleted successfully.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
SPDRIVER_1.37.0.193 => Service deleted successfully.
c:\RecInfo => Moved successfully.
"C:\Program Files\ShopperPro" => File/Directory not found.
"c:\program files\movies app" => File/Directory not found.
C:\Program Files\IObit => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Zdena\Downloads\zoek.exe => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Zdena\Desktop\zoek.exe => Moved successfully.
C:\Users\Zdena\Downloads\zoek.zip => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\system32\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Zdena\Downloads\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Zdena\Desktop\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Zdena\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Zdena\Desktop\JRT.exe => Moved successfully.
C:\Users\Zdena\Downloads\JRT.exe => Moved successfully.
C:\Users\Zdena\Desktop\Addition.txt => Moved successfully.
C:\Users\Zdena\Desktop\FRST.txt => Moved successfully.
C:\Users\Zdena\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\Zdena\Downloads\FRST.exe => Moved successfully.
C:\Users\Zdena\Downloads\FRST64.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9444EA8-C79D-4573-A915-4473165D9652}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9444EA8-C79D-4573-A915-4473165D9652}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41" => Key deleted successfully.
C:\ProgramData\TEMP => ":0E660858" ADS removed successfully.
C:\ProgramData\TEMP => ":561568A4" ADS removed successfully.
C:\ProgramData\TEMP => ":9C68C476" ADS removed successfully.
C:\ProgramData\TEMP => ":BB24555F" ADS removed successfully.
C:\ProgramData\TEMP => ":DF695222" ADS removed successfully.
C:\Users\Zdena\Downloads\message_20317.eml => ":OECustomProperty" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 251.1 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Ran by Zdena at 2014-09-22 22:57:34 Run:1
Running from C:\Users\Zdena\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [recinfo435] => c:\RecInfo\RecInfo.exe [2764800 2007-10-23] ()
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-01-11] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [144784 2008-06-10] (Sun Microsystems, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-02-08] (Google Inc.)
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.exe
HKU\S-1-5-21-54195102-1349951187-670571874-1000\...\Run: [Advanced SystemCare 7] => C:\Program Files\IObit\Advanced SystemCare 7\ASCTray.exe [2288928 2014-02-11] (IObit)
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies app\datamngr\x64\apcrtldr.dll <===== ATTENTION
HKLM\...\AppCertDlls: [x86] -> c:\program files\movies app\datamngr\apcrtldr.dll <===== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll (IObit)
BHO: Skype add-on (mastermind) -> {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
FF Homepage: hxxp://www.search.ask.com/?o=APN10648A& ... 84-326&t=4
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
FF Extension: No Name - C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com [Not Found]
R2 AdvancedSystemCareService7; C:\Program Files\IObit\Advanced SystemCare 7\ASCService.exe [881952 2014-01-14] (IObit)
S2 DatamngrCoordinator2; C:\Program Files\Movies App\Datamngr\DatamngrCoordinator.exe [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 cpuz133; \??\C:\Users\Zdena\AppData\Local\Temp\cpuz133\cpuz133_x32.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 SPDRIVER_1.37.0.193; \??\C:\Program Files\ShopperPro\JSDriver\1.37.0.193\jsdrv.sys [X]
c:\RecInfo
C:\Program Files\ShopperPro
c:\program files\movies app
C:\Program Files\IObit
2014-09-22 00:35 - 2014-09-21 21:33 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 21:37 - 2014-09-22 05:08 - 00049201 _____ () C:\zoek-results.log
2014-09-21 21:26 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Downloads\zoek.exe
2014-09-21 21:21 - 2014-09-22 00:21 - 00000000 ____D () C:\zoek_backup
2014-09-21 21:21 - 2014-09-21 21:26 - 01290752 _____ () C:\Users\Zdena\Desktop\zoek.exe
2014-09-21 21:20 - 2014-09-21 21:21 - 04114148 _____ () C:\Users\Zdena\Downloads\zoek.zip
2014-09-21 16:17 - 2014-09-22 06:38 - 00001426 _____ () C:\Windows\setupact.log
2014-09-21 16:17 - 2014-09-21 16:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-21 15:55 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-09-21 15:54 - 2014-09-21 15:59 - 00000000 ____D () C:\AdwCleaner
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Downloads\adwcleaner_3.310.exe
2014-09-21 15:53 - 2014-09-21 15:53 - 01373475 _____ () C:\Users\Zdena\Desktop\adwcleaner_3.310.exe
2014-09-21 15:52 - 2014-09-21 15:51 - 00019948 _____ () C:\Users\Zdena\Desktop\JRT.txt
2014-09-21 14:41 - 2014-09-21 14:41 - 00000000 ____D () C:\Windows\ERUNT
2014-09-21 14:41 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Desktop\JRT.exe
2014-09-21 14:39 - 2014-09-21 14:39 - 01027006 _____ (Thisisu) C:\Users\Zdena\Downloads\JRT.exe
2014-09-21 11:48 - 2014-09-21 11:48 - 00039201 _____ () C:\Users\Zdena\Desktop\Addition.txt
2014-09-21 11:46 - 2014-09-22 06:39 - 00019186 _____ () C:\Users\Zdena\Desktop\FRST.txt
2014-09-21 10:30 - 2014-09-21 10:31 - 00112640 _____ (forum.viry.cz) C:\Users\Zdena\Desktop\FRSTLauncher.exe
2014-09-21 10:34 - 2014-09-21 10:34 - 01097728 _____ (Farbar) C:\Users\Zdena\Downloads\FRST.exe
2014-09-21 10:22 - 2014-09-21 10:23 - 02105856 _____ (Farbar) C:\Users\Zdena\Downloads\FRST64.exe
Task: {A9444EA8-C79D-4573-A915-4473165D9652} - \SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41 No Task File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:561568A4
AlternateDataStreams: C:\ProgramData\TEMP:9C68C476
AlternateDataStreams: C:\ProgramData\TEMP:BB24555F
AlternateDataStreams: C:\ProgramData\TEMP:DF695222
AlternateDataStreams: C:\Users\Zdena\Downloads\message_20317.eml:OECustomProperty
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\recinfo435 => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect" => Value not found.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SPDriver => value deleted successfully.
HKU\S-1-5-21-54195102-1349951187-670571874-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => Value not found.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully.
HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls\\x86 => value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => Value was restored successfully.
HKLM\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
Default URLSearchHook was restored successfully .
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully.
"HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}" => Key deleted successfully.
"HKCR\CLSID\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}" => Key deleted successfully.
Firefox homepage deleted successfully.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\143f44cf-d99c-4e45-8cd9-ef929de77aa8@bdbf6038-0097-480c-8d8e-fc48e28131a8.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\2eb528f3-950d-48a3-be4b-5d7de6c8331e@a41e199b-6ca4-4d23-ab87-73f2d1973314.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\9321b276-2c2e-4c5f-bd04-b8118e512707@c0c8a2d6-3275-4cac-a0b2-52e936311db9.com => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\{d4a1f3a7-8481-4e22-ab44-b86f7a60f9f2} => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\Extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} => not found.
C:\Users\Zdena\AppData\Roaming\Mozilla\Firefox\Profiles\tm736s2j.default\extensions\sonnypenn@aol.com => not found.
AdvancedSystemCareService7 => Service not found.
DatamngrCoordinator2 => Service deleted successfully.
blbdrive => Service deleted successfully.
cpuz133 => Service deleted successfully.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
SPDRIVER_1.37.0.193 => Service deleted successfully.
c:\RecInfo => Moved successfully.
"C:\Program Files\ShopperPro" => File/Directory not found.
"c:\program files\movies app" => File/Directory not found.
C:\Program Files\IObit => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Zdena\Downloads\zoek.exe => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Zdena\Desktop\zoek.exe => Moved successfully.
C:\Users\Zdena\Downloads\zoek.zip => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\system32\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Zdena\Downloads\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Zdena\Desktop\adwcleaner_3.310.exe => Moved successfully.
C:\Users\Zdena\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Zdena\Desktop\JRT.exe => Moved successfully.
C:\Users\Zdena\Downloads\JRT.exe => Moved successfully.
C:\Users\Zdena\Desktop\Addition.txt => Moved successfully.
C:\Users\Zdena\Desktop\FRST.txt => Moved successfully.
C:\Users\Zdena\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\Zdena\Downloads\FRST.exe => Moved successfully.
C:\Users\Zdena\Downloads\FRST64.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9444EA8-C79D-4573-A915-4473165D9652}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9444EA8-C79D-4573-A915-4473165D9652}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_3931343739303835392d3437415a556c2a3223346c41" => Key deleted successfully.
C:\ProgramData\TEMP => ":0E660858" ADS removed successfully.
C:\ProgramData\TEMP => ":561568A4" ADS removed successfully.
C:\ProgramData\TEMP => ":9C68C476" ADS removed successfully.
C:\ProgramData\TEMP => ":BB24555F" ADS removed successfully.
C:\ProgramData\TEMP => ":DF695222" ADS removed successfully.
C:\Users\Zdena\Downloads\message_20317.eml => ":OECustomProperty" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 251.1 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Prosím o kontrolu
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
Napiste jak se chova PC


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
Po posledních krocích se mi zatím njepodařilo systém spustit, snad to nějak dám dohromady.
Re: Prosím o kontrolu
Na cem to ztroskota?? Pripadne pokud nepujde, tak pri restartu F8 a zvolit Posledni znama funkcni konfigurace
-
- Návštěvník
- Příspěvky: 13
- Registrován: 21 zář 2014 09:19
Re: Prosím o kontrolu
Tak už je to snad v pořádku. Myslím, že toto bude spíš problém HW - možná přehřívání. Zkusím ho tedy rozdělat a vyčistit i "zvenčí".
Jinak se systém chová tak, jak by měl. Je mnohem rychlejší a žádná vyskakovací okna se neobjevují.
Děkuji moc a přeji hezký den.
Jinak se systém chová tak, jak by měl. Je mnohem rychlejší a žádná vyskakovací okna se neobjevují.
Děkuji moc a přeji hezký den.