IstartSurf
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
-
Davidas1
IstartSurf
Dobrý den, prosím o radu, jak mám odstranit program IstartSurf?? Vždy při zapnutí internetu se mi objeví stránka Istartsurf ://
Předem děkuji .
Předem děkuji .
Re: IstartSurf
Zdravim 
Jelikoz vestit zatim neumim (ale delam na tom
) a nevim ani, jaky mate operacni system, dejte nejprve log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=130786 .
Jelikoz vestit zatim neumim (ale delam na tom
Možnost podpořit naše fórum https://platba.viry.cz/payment/
-
Davidas1
Re: IstartSurf
vygenerovalo mi to toto :
Logfile of random's system information tool 1.10 (written by random/random)
Run by user at 2014-11-17 15:21:20
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 6 GB (13%) free of 44 GB
Total RAM: 1919 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:21:52, on 17.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Users\user\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\user\Downloads\RSIT.exe
C:\Program Files\trend micro\user.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {96f454ea-9d38-474f-b504-56193e00c1a5} - (no file)
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_45\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_45\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: (no name) - {96f454ea-9d38-474f-b504-56193e00c1a5} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "H:\David\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\user\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\user\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: CCC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files\MyPC Backup\BackupStack.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
--
End of file - 9141 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf2a13a3debce4.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"faststartff@gmail.com"=C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\faststartff@gmail.com
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.7.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.7.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\
donottrackplus@abine.com
faststartff@gmail.com
{2FD73609-F02D-3849-D765-5F8F93ECC348}
{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
{96f454ea-9d38-474f-b504-56193e00c1a5}
{d1dac034-9fd9-4c13-a388-d2e10e57707f}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\
Ask.xml
askcom.xml
conduit.xml
googlecustomsearch.xml
ividi.xml
my-web-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files\SupTab\SupTab.dll [2014-08-11 507904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.7.0_45\bin\ssv.dll [2014-06-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.7.0_45\bin\jp2ssv.dll [2014-06-08 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]
{96f454ea-9d38-474f-b504-56193e00c1a5}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-08-30 4858968]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"LogMeIn Hamachi Ui"=H:\David\hamachi-2-ui.exe --auto-start []
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""=C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe []
"SkyDrive"=C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2014-10-27 277672]
"Sony PC Companion"=C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [2014-10-15 468192]
"cz.seznam.software.autoupdate"=C:\Users\user\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\user\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"DAEMON Tools Lite"=I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid]
C:\Users\user\AppData\Local\iLivid\iLivid.exe -autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2013-02-05 4272624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]
C:\Windows\inf\ntvdm.vbe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files\Zrychleni Pocitace\PCSUNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart PC Cleaner]
C:\Program Files\Smart PC Cleaner\SPCLauncher.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\user\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
C:\Program Files\AVG Secure Search\vprot.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
C:\PROGRA~1\MYPCBA~1\MYPCBA~1.EXE [2014-09-19 3143264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~1\Office12\ONENOTEM.EXE [2009-02-26 97680]
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-11-17 15:21:20 ----D---- C:\Program Files\trend micro
2014-11-17 15:21:19 ----D---- C:\rsit
2014-11-17 13:55:23 ----D---- C:\ProgramData\Samsung
2014-11-16 17:25:11 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-11-16 17:24:23 ----D---- C:\ProgramData\Malwarebytes
2014-10-28 19:02:17 ----D---- C:\xampp
2014-10-28 18:59:33 ----D---- C:\Users\user\AppData\Roaming\Notepad++
2014-10-28 18:59:33 ----D---- C:\Program Files\Notepad++
2014-10-28 18:51:25 ----D---- C:\Users\user\AppData\Roaming\Hamachi
2014-10-28 18:50:50 ----A---- C:\Windows\system32\drivers\hamachi.sys
======List of files/folders modified in the last 1 month======
2014-12-06 12:19:34 ----D---- C:\Program Files\HP
2014-11-17 15:21:34 ----D---- C:\Windows\Temp
2014-11-17 15:21:20 ----RD---- C:\Program Files
2014-11-17 15:19:30 ----D---- C:\Program Files\Steam
2014-11-17 15:13:27 ----D---- C:\Program Files\BitComet
2014-11-17 14:59:53 ----D---- C:\Users\user\AppData\Roaming\Seznam.cz
2014-11-17 14:59:13 ----D---- C:\Windows\System32
2014-11-17 14:59:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-17 14:52:03 ----D---- C:\Windows\system32\catroot
2014-11-17 14:07:03 ----D---- C:\Windows
2014-11-17 14:06:21 ----SHD---- C:\Windows\system32\AI_RecycleBin
2014-11-17 14:06:21 ----SHD---- C:\Windows\Installer
2014-11-17 14:06:06 ----SHD---- C:\System Volume Information
2014-11-17 14:05:10 ----HD---- C:\Program Files\InstallShield Installation Information
2014-11-17 14:04:00 ----D---- C:\Windows\system32\drivers
2014-11-17 14:03:42 ----D---- C:\Windows\system32\Tasks
2014-11-17 13:56:33 ----D---- C:\Program Files\Samsung
2014-11-17 13:56:27 ----D---- C:\Windows\inf
2014-11-17 13:56:06 ----D---- C:\Windows\system32\DriverStore
2014-11-17 13:55:23 ----HD---- C:\ProgramData
2014-11-17 13:51:30 ----D---- C:\Windows\Microsoft.NET
2014-11-17 13:41:05 ----D---- C:\Users\user\AppData\Roaming\uTorrent
2014-11-17 13:34:43 ----D---- C:\Users\user\AppData\Roaming\GeoGet
2014-11-16 17:24:23 ----D---- C:\totalcmd
2014-11-14 19:32:39 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-11-13 19:37:02 ----D---- C:\Windows\Prefetch
2014-11-01 13:06:01 ----D---- C:\Program Files\Opera
2014-10-28 19:12:37 ----D---- C:\Windows\winsxs
2014-10-28 18:49:56 ----D---- C:\Temp
2014-10-21 01:33:14 ----D---- C:\Program Files\SupTab
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-08-30 49376]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-08-30 177864]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2014-04-12 320120]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw.sys [2014-07-08 52920]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-08-30 61680]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-08-30 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-08-30 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-08-30 56080]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-04-12 243128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-08-30 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-08-30 66336]
R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet - adaptér; C:\Windows\system32\DRIVERS\l260x86.sys [2009-07-13 29184]
R3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2014-10-28 25280]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-12-20 2385920]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam; C:\Windows\System32\Drivers\StkCMini.sys [2012-12-20 1260672]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [2014-02-10 12320]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 alwl6eq0;alwl6eq0; C:\Windows\system32\drivers\alwl6eq0.sys []
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2013-02-05 49664]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-11-16 114904]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2010-08-16 16472]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2010-08-16 11104]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2009-09-21 98560]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 14848]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 123776]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2012-12-20 565248]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-08-30 46808]
R2 BackupStack;Computer Backup (MyPC Backup); C:\Program Files\MyPC Backup\BackupStack.exe [2014-09-19 36936]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-08-11 694784]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service; C:\Windows\System32\StkCSrv.exe [2012-12-20 24576]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2014-03-22 1805624]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-22 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-14 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-22 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-05-30 108032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-25 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-05-29 543424]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-22 1343400]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by user at 2014-11-17 15:21:20
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 6 GB (13%) free of 44 GB
Total RAM: 1919 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:21:52, on 17.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
C:\Users\user\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\user\Downloads\RSIT.exe
C:\Program Files\trend micro\user.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {96f454ea-9d38-474f-b504-56193e00c1a5} - (no file)
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0_45\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.7.0_45\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: (no name) - {96f454ea-9d38-474f-b504-56193e00c1a5} - (no file)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "H:\David\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\user\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\user\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: CCC.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files\MyPC Backup\BackupStack.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files\Sony\Sony PC Companion\PCCService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
--
End of file - 9141 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf2a13a3debce4.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
prefs.js - "browser.search.useDBForOrder" - "false"
prefs.js - "browser.startup.homepage" - "http://www.istartsurf.com/?type=hp&ts=1 ... XX5VG02CS6"
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"faststartff@gmail.com"=C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\faststartff@gmail.com
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.7.0_45\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.7.0_45\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\plugins\
nppdf32.dll
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\
donottrackplus@abine.com
faststartff@gmail.com
{2FD73609-F02D-3849-D765-5F8F93ECC348}
{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
{96f454ea-9d38-474f-b504-56193e00c1a5}
{d1dac034-9fd9-4c13-a388-d2e10e57707f}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\
Ask.xml
askcom.xml
conduit.xml
googlecustomsearch.xml
ividi.xml
my-web-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files\SupTab\SupTab.dll [2014-08-11 507904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.7.0_45\bin\ssv.dll [2014-06-08 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.7.0_45\bin\jp2ssv.dll [2014-06-08 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]
{96f454ea-9d38-474f-b504-56193e00c1a5}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-08-30 4858968]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"LogMeIn Hamachi Ui"=H:\David\hamachi-2-ui.exe --auto-start []
"seznam-listicka-distribuce"=C:\Program Files\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""=C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe []
"SkyDrive"=C:\Users\user\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [2014-10-27 277672]
"Sony PC Companion"=C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [2014-10-15 468192]
"cz.seznam.software.autoupdate"=C:\Users\user\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\user\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"DAEMON Tools Lite"=I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
I:\David\Programy na spuštění her\Demon Tools lite\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid]
C:\Users\user\AppData\Local\iLivid\iLivid.exe -autorun []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2013-02-05 4272624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]
C:\Windows\inf\ntvdm.vbe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp]
C:\Program Files\Zrychleni Pocitace\PCSUNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart PC Cleaner]
C:\Program Files\Smart PC Cleaner\SPCLauncher.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Users\user\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
C:\Program Files\AVG Secure Search\vprot.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
C:\PROGRA~1\MYPCBA~1\MYPCBA~1.EXE [2014-09-19 3143264]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
C:\PROGRA~1\MICROS~1\Office12\ONENOTEM.EXE [2009-02-26 97680]
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.FPS1"=frapsvid.dll
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-11-17 15:21:20 ----D---- C:\Program Files\trend micro
2014-11-17 15:21:19 ----D---- C:\rsit
2014-11-17 13:55:23 ----D---- C:\ProgramData\Samsung
2014-11-16 17:25:11 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-11-16 17:24:24 ----A---- C:\Windows\system32\drivers\mbam.sys
2014-11-16 17:24:23 ----D---- C:\ProgramData\Malwarebytes
2014-10-28 19:02:17 ----D---- C:\xampp
2014-10-28 18:59:33 ----D---- C:\Users\user\AppData\Roaming\Notepad++
2014-10-28 18:59:33 ----D---- C:\Program Files\Notepad++
2014-10-28 18:51:25 ----D---- C:\Users\user\AppData\Roaming\Hamachi
2014-10-28 18:50:50 ----A---- C:\Windows\system32\drivers\hamachi.sys
======List of files/folders modified in the last 1 month======
2014-12-06 12:19:34 ----D---- C:\Program Files\HP
2014-11-17 15:21:34 ----D---- C:\Windows\Temp
2014-11-17 15:21:20 ----RD---- C:\Program Files
2014-11-17 15:19:30 ----D---- C:\Program Files\Steam
2014-11-17 15:13:27 ----D---- C:\Program Files\BitComet
2014-11-17 14:59:53 ----D---- C:\Users\user\AppData\Roaming\Seznam.cz
2014-11-17 14:59:13 ----D---- C:\Windows\System32
2014-11-17 14:59:13 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-17 14:52:03 ----D---- C:\Windows\system32\catroot
2014-11-17 14:07:03 ----D---- C:\Windows
2014-11-17 14:06:21 ----SHD---- C:\Windows\system32\AI_RecycleBin
2014-11-17 14:06:21 ----SHD---- C:\Windows\Installer
2014-11-17 14:06:06 ----SHD---- C:\System Volume Information
2014-11-17 14:05:10 ----HD---- C:\Program Files\InstallShield Installation Information
2014-11-17 14:04:00 ----D---- C:\Windows\system32\drivers
2014-11-17 14:03:42 ----D---- C:\Windows\system32\Tasks
2014-11-17 13:56:33 ----D---- C:\Program Files\Samsung
2014-11-17 13:56:27 ----D---- C:\Windows\inf
2014-11-17 13:56:06 ----D---- C:\Windows\system32\DriverStore
2014-11-17 13:55:23 ----HD---- C:\ProgramData
2014-11-17 13:51:30 ----D---- C:\Windows\Microsoft.NET
2014-11-17 13:41:05 ----D---- C:\Users\user\AppData\Roaming\uTorrent
2014-11-17 13:34:43 ----D---- C:\Users\user\AppData\Roaming\GeoGet
2014-11-16 17:24:23 ----D---- C:\totalcmd
2014-11-14 19:32:39 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-11-13 19:37:02 ----D---- C:\Windows\Prefetch
2014-11-01 13:06:01 ----D---- C:\Program Files\Opera
2014-10-28 19:12:37 ----D---- C:\Windows\winsxs
2014-10-28 18:49:56 ----D---- C:\Temp
2014-10-21 01:33:14 ----D---- C:\Program Files\SupTab
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-08-30 49376]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-08-30 177864]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2014-04-12 320120]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw;{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw; C:\Windows\system32\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw.sys [2014-07-08 52920]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-08-30 61680]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-08-30 770344]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-08-30 369584]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2013-08-30 56080]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-04-12 243128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-08-30 29816]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-08-30 66336]
R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet - adaptér; C:\Windows\system32\DRIVERS\l260x86.sys [2009-07-13 29184]
R3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athr.sys [2009-07-13 1096704]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2014-10-28 25280]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-12-20 2385920]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam; C:\Windows\System32\Drivers\StkCMini.sys [2012-12-20 1260672]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys [2014-02-10 12320]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 alwl6eq0;alwl6eq0; C:\Windows\system32\drivers\alwl6eq0.sys []
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 393728]
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2013-02-05 49664]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2014-11-16 114904]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2010-08-16 16472]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2010-08-16 11104]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\Windows\system32\DRIVERS\ss_bus.sys [2009-09-21 98560]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\Windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 14848]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\Windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 123776]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 36352]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2012-12-20 565248]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-08-30 46808]
R2 BackupStack;Computer Backup (MyPC Backup); C:\Program Files\MyPC Backup\BackupStack.exe [2014-09-19 36936]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-08-11 694784]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service; C:\Windows\System32\StkCSrv.exe [2012-12-20 24576]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe [2014-03-22 1805624]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 1713904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-22 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-14 267440]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-22 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-05-30 108032]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-25 114288]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-05-29 543424]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-12-22 1343400]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: IstartSurf
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
vyosek napsal:Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
vyosek napsal:Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Možnost podpořit naše fórum https://platba.viry.cz/payment/
-
Davidas1
Re: IstartSurf
Ty dva programy jsem odinstaloval, ale dál to nechápu-mám stáhnout 1 aplikaci a jsou tam 2 návody... jak to mám chápat ?
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: IstartSurf
Zdravím a abychom to neprotahovali:
jsou to tři návody na použití tří programů - takže všechny
kolega to pak vyhodnotí
jsou to tři návody na použití tří programů - takže všechny
kolega to pak vyhodnotí
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
-
Davidas1
Re: IstartSurf
Dobrý den, použil jsem zatím jen awdcleaner, a problémy s istartSurfem ustaly. Mám tu toto téma rozvíjet dál? Pokud ne, všem moc děkuji 
Re: IstartSurf
Aby to nebylo zitra zpet, doporucuji pouzit vsechny 3, tak jak se pise v navodu 
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Re: IstartSurf
Ale rad bych pak videl logy. Je treba to docistit.
Možnost podpořit naše fórum https://platba.viry.cz/payment/
-
Davidas1
Re: IstartSurf
Tak tady přikládám logy :
z JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 7 Professional x86
Ran by user on po 17.11.2014 at 16:24:52,41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BD641314-9261-4934-AF7C-4622F42C2EDD}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\ja7w1r9c.default\smartbar
Emptied folder: C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\ja7w1r9c.default\minidumps [91 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 17.11.2014 at 16:30:02,12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log z ADwCleaner:
# AdwCleaner v4.101 - Report created 17/11/2014 at 15:52:52
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : user - USER-PC
# Running from : C:\Users\user\Desktop\adwcleaner_4.101.exe
# Option : Scan
***** [ Services ] *****
Service Found : BackupStack
Service Found : IePluginServices
Service Found : {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw
***** [ Files / Folders ] *****
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Ask.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Askcom.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Conduit.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\ividi.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\my-web-search.xml
File Found : C:\users\user\AppData\Roaming\speedanalysis.ico
File Found : C:\Windows\system32\\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw.sys
File Found : C:\Windows\system32\roboot.exe
Folder Found : C:\Program Files\Common Files\Spigot
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\File Type Assistant
Folder Found : C:\Program Files\Movies Toolbar
Folder Found : C:\Program Files\MyPC Backup
Folder Found : C:\Program Files\SupTab
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\Datamngr
Folder Found : C:\ProgramData\DataMngr
Folder Found : C:\ProgramData\IBUpdaterService
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\SoftSafe
Folder Found : C:\ProgramData\wincert
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\users\user\AppData\Local\apn
Folder Found : C:\users\user\AppData\Local\Conduit
Folder Found : C:\users\user\AppData\Local\FileTypeAssistant
Folder Found : C:\users\user\AppData\Local\ilividmoviestoolbar181
Folder Found : C:\users\user\AppData\LocalLow\Conduit
Folder Found : C:\users\user\AppData\LocalLow\iac
Folder Found : C:\users\user\AppData\LocalLow\ilividmoviestoolbar181
Folder Found : C:\users\user\AppData\LocalLow\PriceGong
Folder Found : C:\users\user\AppData\Roaming\7go
Folder Found : C:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\faststartff@gmail.com
Folder Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
Folder Found : C:\users\user\AppData\Roaming\OpenCandy
Folder Found : C:\users\user\AppData\Roaming\PerformerSoft
Folder Found : C:\users\user\AppData\Roaming\Solvusoft
Folder Found : C:\users\user\AppData\Roaming\SpeedAnalysis3
Folder Found : C:\users\user\Documents\smart pc cleaner
***** [ Scheduled Tasks ] *****
Task Found : ProgramRefresh-ATFST
Task Found : ProgramUpdateCheck
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=14077689 ... XX5VG02CS6
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\APNDTX
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\pdfforge
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\AppDataLow\Software\Smartbar
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Bitberry
Key Found : HKCU\Software\Classes\iLivid.torrent
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\filescout
Key Found : HKCU\Software\FileTypeAssistant
Key Found : HKCU\Software\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\ilividmoviestoolbar181
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\iVIDI Plugin
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4D2BA467-3AD4-45D9-AA6D-DA4F4310C985}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5F52C651-A33D-45C3-A82D-514BEA5875D2}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9E646E93-E9FE-4B93-B6BC-B5224BE61D4E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\powerpack
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SupHpUISoft
Key Found : HKCU\Software\UpdateStar
Key Found : HKCU\Software\USyndication
Key Found : HKCU\Software\usyndication.com
Key Found : HKLM\SOFTWARE\Classes\7Go Games.ScriptHostObject
Key Found : HKLM\SOFTWARE\Classes\7Go Games.ScriptHostObject.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Found : HKLM\SOFTWARE\Classes\AppID\{685F23D9-FCFD-475C-B56A-362645945C5A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Found : HKLM\SOFTWARE\Classes\iLivid.torrent
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Found : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject
Key Found : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}
Key Found : HKLM\SOFTWARE\microsoft\shared tools\msconfig\startupreg\PCSpeedUp
Key Found : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbar181CR
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trusted Software Assistant_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Found : HKLM\SOFTWARE\PIP
Key Found : HKLM\SOFTWARE\Speedchecker Limited
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\Uniblue
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1407 ... earchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1407 ... earchTerms}
-\\ Mozilla Firefox v32.0.3 (x86 cs)
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.BT_Stats.enc", "eyJsYXN0X2xvZyI6MTM2NDMyMTQ3NCwidXVpZCI6Nzc4NTk1MzMyODU4NDAsInNlcV9pZCI6Niwic3NiIjoxMzYzNTM5MTIxfQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FF19Solved", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FirstTime", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FirstTimeFF3", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.PG_ENABLE", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.PG_ENABLE.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN17420652583231028&UM=1&q=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.UserID", "UN17420652583231028");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.addressBarTakeOverEnabledInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.autoDisableScopes", -1);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.browser.search.defaultthis.engineName", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.countryCode", "CZ");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.defaultSearch", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.enableFix404ByUser", "FALSE");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.enableSearchFromAddressBar", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.firstTimeDialogOpened", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundError", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundErrorByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundErrorInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixUrls", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fullUserID", "UN17420652583231028.UP.20130712161855");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.homepageuserchanged", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installDate", "17/3/2013 17:46:41");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installType", "xpe");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installUsage", "2013-03-17T19:51:46.16269+03:00");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installUsageEarly", "2013-03-17T19:51:40.4373799+03:00");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installerVersion", "1.3.6.5");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isCheckedStartAsHidden", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isFirstTimeToolbarLoading", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.keyword", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3289075&octid=CT3289075&SearchSource=15&CUI=UN17420652583231028&SSPV=&Lay=1&UM=\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.lastVersion", "10.20.0.513");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appStateReportTime.enc", "MTM2NDMwOTE0MDU3OQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appState_CouponBuddy.enc", "b24=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appState_PriceGong.enc", "b24=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnNEaWFsb2ciOnsiZGlzcGxheU5h[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6IjQzZmVjMDg1LWNkMzktNGQyZi05MDZhLTAyNTdkZjM2YzlhYiIsImRvbWFpbnMiOls[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_currentVersion.enc", "MS40LjQuNg==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_eventsCache.enc", "eyJjNWIwYWE2MS1jOTA1LTRmNzctYTU0YS04ODBiMjQ1Yjc0NjgiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjpbIldlbGNvbWUiLCJWaWV3Il0sInVuaXF1ZUlkIjoiYzViMGFhNjEtYzkwNS00Z[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_first_time.enc", "MQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_gadgetOpen.enc", "MA==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_lastLoginTime.enc", "MTM2NDMwOTEzOTM2Ng==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIg[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_settings1.4.3.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_userId.enc", "NDg1ZDYxZTItNjE4Yy00MTc3LTgyMTYtYmFjODk1MGEzYWIz");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_user_apps_selection.enc", "");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.migrateAppsAndComponents", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxps%3A%2F%2Fwww.google.cz%2F%3Fgws_rd%3Dcr%26ei%3D1p6wUuTJFMmL4gTi0IGoCQ%23q%3Dseznam\",\"EB_MAIN_FRAME_TITLE\":\"seznam%20-%20[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.openThankYouPage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.openUninstallPage", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.originalSearchAddressUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.revertSettingsEnabled", "FALSE");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.search.searchAppId", "130064539389933152");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.search.searchCount", "0");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchFromAddressBarEnabledByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchInNewTabEnabledByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchInNewTabEnabledInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchSuggestEnabledByUser", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3289075\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentControlv6.OurToolbar.com//xpi\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl_v6 \"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_Configuration_lastUpdate", "1383234107957");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1363539108672");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_appsMetadata_lastUpdate", "1364236598900");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1363539108507");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1363539103379");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1363539108168");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_location_lastUpdate", "1373386860745");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.14.370.24_lastUpdate", "1363539108745");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.14.370.524_lastUpdate", "1364234334947");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.15.0.562_lastUpdate", "1369368840761");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.2.509_lastUpdate", "1373386861201");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.4.519_lastUpdate", "1375094193757");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.70.505_lastUpdate", "1379256403004");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.20.0.513_lastUpdate", "1383234108699");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1363539108387");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_searchAPI_lastUpdate", "1383234108195");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_serviceMap_lastUpdate", "1383234107879");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_toolbarContextMenu_lastUpdate", "1363539108296");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_toolbarSettings_lastUpdate", "1383234108082");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_translation_lastUpdate", "1383234108154");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.settingsINI", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.shouldFirstTimeDialog", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.showToolbarPermission", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.CTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.Uninstall", "0");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.homepage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.isHidden", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.toolbarName", "uTorrentControl_v6 ");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.startPage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarBornServerTime", "17-3-2013");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarCurrentServerTime", "31-10-2013");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarDisabled", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarLoginClientTime", "Sun Mar 17 2013 17:51:48 GMT+0100");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.url_history0001.enc", "aHR0cDovL3d3dy53YXR0c2VuZ2xpc2guY29tL2xldG5pLWphenlrb3ZlLXRhYm9yeS9wcmlobGFza3ktbmEtdGFib3IvNjU4MC1wcmltZXN0c2t5LXRhYm9yLXMtYW5nbGljdGlub3UtYmFrb3Ytbi1qaXpl[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1387306741621,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitSearchEngineList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitSearchUrlList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz[...]
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("browser.newtab.url", "hxxp://www.istartsurf.com/newtab/?type=nt&ts=1 ... XX5VG02CS6");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "uTorrentControl_v6 Customized Web Search");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&CUI=UN17420652583231028&UM=1&SearchSource=3&q={searchTerms}");
[ja7w1r9c.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.id", "\"13456c7f-d618-c528-8573-b234182f37b2\"");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.mzID", "93");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.uuid", "\"171fc5c0-220e-11e3-8099-0025901ef77c\"");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.admin", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.aflt", "3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.appId", "{685F23D9-FCFD-475C-B56A-362645945C5A}");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.autoRvrt", "false");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dfltLng", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dfltSrch", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dnsErr", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.excTlbr", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.ffxUnstlRst", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hmpg", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hmpgUrl", "hxxp://search.ividi.org/?src=tbhp&id=58e1aba6000000000000001d6010cccc&affilt=3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hpOld0", "about:home");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.id", "58e1aba6000000000000001d6010cccc");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.instlDay", "15997");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.instlRef", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.kw_url", "hxxp://search.ividi.org/?src=tbsp&id=58e1aba6000000000000001d6010cccc&affilt=3&q=");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.newTab", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.newTabUrl", "hxxp://search.ividi.org/?q={searchTerms}&src=tbnt&id=58e1aba6000000000000001d6010cccc&affilt=3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.prdct", "ividi");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.prtnrId", "ividi");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.rvrt", "false");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.smplGrp", "none");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.srchPrvdr", "Search ");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.tlbrId", "base");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.tlbrSrchUrl", "hxxp://search.ividi.org/?src=tbsp&id=58e1aba6000000000000001d6010cccc&affilt=3&q=");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsn", "1.8.23.0");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsnTs", "1.8.23.014:39:25");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsni", "1.8.23.0");
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si=[...]
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&p2=^UX^xdm007^YY^cz&si=CKiQjeeDtrQCFURY3godR[...]
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.enabled", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.user.defined", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.initialized", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.contextKey", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.installDate", "2012122518");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerId", "^UX^xdm007^YY^cz");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerSubId", "CKiQjeeDtrQCFURY3godRxsAbA");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.success", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.toolbarId", "041ACE5B-510D-4FDB-AFEA-BDBB45E66115");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1396709834189");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.defaultSearch", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.homePageEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.keywordEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.tabEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.searchHistory", "dlouhonovice||seznam.cz||||umgreifen||bazény baumax||bazény obi||mountfield bazény||vjera hensova||www.google.com||google.cz");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.weather.location", "10001");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "mapsgalaxy@mindspark.com");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289075&CUI=UN17420652583231028&UM=1&SearchSource=13");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN17420652583231028&UM=1&q=,hxxp://search.conduit.com/ResultsExt.aspx?cti[...]
[ja7w1r9c.default] - Line Found : user_pref("smartbar.machineId", "VHN2ZWSJU7WJFM+6EMYAMQ2DCILOH4I22ZJ/HZHDBQHXC8AUAGWJPHMHRZMWSV3ZXCCTFM2TR3K+G1TH9RWRRW");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalHomepage", "hxxps://www.google.cz/");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalSearchAddressUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si=[...]
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalSearchEngine", "Google");
-\\ Google Chrome v38.0.2125.122
-\\ Opera v25.0.1614.68
*************************
AdwCleaner[R0].txt - [306 octets] - [17/11/2014 15:41:00]
AdwCleaner[R1].txt - [306 octets] - [17/11/2014 15:43:21]
AdwCleaner[R2].txt - [38595 octets] - [17/11/2014 15:52:52]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [38656 octets] ##########
A nakonec log z zoek:
Zoek.exe v5.0.0.0 Updated 16-November-2014
Tool run by user on st 18.07.2007 at 1:05:47,48.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\user\Desktop\zoek.exe [Scan all users] [Script inserted]
==== Older Logs ======================
C:\zoek-results2014-11-17-154426.log 1303 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B9497038-4743-4322-89E0-89440634CE68} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\prefs.js:
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
user.js not found
---- Lines Yawtix removed from prefs.js ----
user_pref("extensions.Yawtix.aul", "1407136410566");
user_pref("extensions.Yawtix.irl", true);
user_pref("extensions.Yawtix.is", "IM27lsCZ");
user_pref("extensions.Yawtix.ug", "5B4D3B00-DBDF-4A12-BD0F-40D1272FDAE9");
---- Lines foxlingo removed from prefs.js ----
user_pref("foxlingo.installed", true);
user_pref("foxlingo.usetoolbar", false);
user_pref("foxlingo.version", "1");
---- Lines {96F454EA-9D38-474F-B504-56193E00C1A5} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST So
---- FireFox user.js and prefs.js backups ----
prefs_18.07.2007_0125_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Špidla Data Processing, s.r.o not found
C:\PROGRA~2\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted
C:\Users\user\AppData\LocalLow\uTorrentControl_v6 deleted
C:\Program Files\GUT260E.tmp deleted
C:\Program Files\GUM260D.tmp deleted
C:\Program Files\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\found.000 deleted
C:\Users\user\AppData\Roaming\CamStudio.Producer.Data.ini deleted
C:\Users\user\AppData\Roaming\CamStudio.Producer.ini deleted
C:\Users\user\AppData\Roaming\die.bat deleted
C:\Users\user\AppData\Roaming\apachesrvin.vbs deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\user\AppData\Local\CRE deleted
C:\Users\user\AppData\Local\cache deleted
C:\Windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Public\Documents\AlawarWrapper deleted
C:\Users\user\Documents\Add-in Express deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\googlecustomsearch.xml deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\ilividmoviestoolbar181 deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\CT3289075 deleted
C:\Users\user\Desktop\Continue installation - Keygen Installer Installation.lnk deleted
C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\{d1dac034-9fd9-4c13-a388-d2e10e57707f} deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} deleted
"C:\Users\user\AppData\Local\{4C77CAB7-FD04-438A-A686-EAE3B14E36F8}" deleted
"C:\Users\user\AppData\Local\{93505646-2FA2-4D9F-949A-BD89F570EE0F}" deleted
"C:\Users\user\AppData\Roaming\pdfconverter" deleted
"C:\Users\user\AppData\Roaming\install" deleted
"C:\Users\user\AppData\Roaming\Samsung" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [09.09.2013 17:07]
==== Firefox Extensions ======================
ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- DoNotTrackMe: Online Privacy Protection - %ProfilePath%\extensions\donottrackplus@abine.com
- Ask New Tabs - %ProfilePath%\extensions\{2FD73609-F02D-3849-D765-5F8F93ECC348}
- iMacros for Firefox - %ProfilePath%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
67D325B5AEB28E381B84E8DE1A90C7A8 - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll - Shockwave Flash
64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre1.7.0_45\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre1.7.0_45\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
F6D12679B9112358AC705A1308156F59 - C:\Users\user\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
C47920B4F36C19F97BD2EC19481387E5 - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll - Pando Web Plugin
F3B0E300AFC94E1A775A2D935A7D384F - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll - Shockwave for Director / Shockwave for Director
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
0D80C49D9A4A3E096296C67BD015F614 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery
A843FC35574ECFD9E7A41C5505A9921B - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
D2377C9458EFEB094E38B8C874AA214C - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
==== Deleted Firefox Extensions ======================
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\donottrackplus@abine.com deleted
==== Chromium Look ======================
==== Chromium Fix ======================
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mbmpjbkgemhgalmeiigcdljkccfcafoj_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_clients5.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_clients5.google.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_mail.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_blog.teesupport.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_blog.teesupport.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc.poradna.net_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc.poradna.net_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_reklama2.viry.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_reklama2.viry.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure-us.imrworldwide.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure-us.imrworldwide.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bleepingcomputer.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bleepingcomputer.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.slunecnice.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.slunecnice.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.stalo-se.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.stalo-se.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.tomasstodola.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.tomasstodola.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.viry.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.viry.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zive.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zive.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_knohfebhibeknbfioecpdmdkjkjdnjnl_0.localstorage deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\opera_discover_0.localstorage deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\opera_startpage_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\http_www.zive.cz_0 deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mbmpjbkgemhgalmeiigcdljkccfcafoj deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{BD641314-9261-4934-AF7C-4622F42C2EDD}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BD641314-9261-4934-AF7C-4622F42C2EDD}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{97DB78A0-51AC-403D-99A8-2D4A35ADF5C1} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
==== Reset Google Chrome ======================
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{00EB810E-E56A-4308-A1E3-AD48DB08A3F8} deleted successfully
HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbar181FF deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart PC Cleaner deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
==== Empty IE Cache ======================
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\ja7w1r9c.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\user\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1797 folders=466 153936598 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\user\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\user\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 18.07.2007 at 0:01:36,52 ======================
z JRT:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 7 Professional x86
Ran by user on po 17.11.2014 at 16:24:52,41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BD641314-9261-4934-AF7C-4622F42C2EDD}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\ja7w1r9c.default\smartbar
Emptied folder: C:\Users\user\AppData\Roaming\mozilla\firefox\profiles\ja7w1r9c.default\minidumps [91 files]
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 17.11.2014 at 16:30:02,12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log z ADwCleaner:
# AdwCleaner v4.101 - Report created 17/11/2014 at 15:52:52
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : user - USER-PC
# Running from : C:\Users\user\Desktop\adwcleaner_4.101.exe
# Option : Scan
***** [ Services ] *****
Service Found : BackupStack
Service Found : IePluginServices
Service Found : {16d667ee-6782-4b21-81df-8ded8ebc3868}Gw
***** [ Files / Folders ] *****
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Ask.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Askcom.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\Conduit.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\ividi.xml
File Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\my-web-search.xml
File Found : C:\users\user\AppData\Roaming\speedanalysis.ico
File Found : C:\Windows\system32\\drivers\{16d667ee-6782-4b21-81df-8ded8ebc3868}Gw.sys
File Found : C:\Windows\system32\roboot.exe
Folder Found : C:\Program Files\Common Files\Spigot
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\File Type Assistant
Folder Found : C:\Program Files\Movies Toolbar
Folder Found : C:\Program Files\MyPC Backup
Folder Found : C:\Program Files\SupTab
Folder Found : C:\ProgramData\AlawarWrapper
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\Datamngr
Folder Found : C:\ProgramData\DataMngr
Folder Found : C:\ProgramData\IBUpdaterService
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\SoftSafe
Folder Found : C:\ProgramData\wincert
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\users\user\AppData\Local\apn
Folder Found : C:\users\user\AppData\Local\Conduit
Folder Found : C:\users\user\AppData\Local\FileTypeAssistant
Folder Found : C:\users\user\AppData\Local\ilividmoviestoolbar181
Folder Found : C:\users\user\AppData\LocalLow\Conduit
Folder Found : C:\users\user\AppData\LocalLow\iac
Folder Found : C:\users\user\AppData\LocalLow\ilividmoviestoolbar181
Folder Found : C:\users\user\AppData\LocalLow\PriceGong
Folder Found : C:\users\user\AppData\Roaming\7go
Folder Found : C:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\faststartff@gmail.com
Folder Found : C:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
Folder Found : C:\users\user\AppData\Roaming\OpenCandy
Folder Found : C:\users\user\AppData\Roaming\PerformerSoft
Folder Found : C:\users\user\AppData\Roaming\Solvusoft
Folder Found : C:\users\user\AppData\Roaming\SpeedAnalysis3
Folder Found : C:\users\user\Documents\smart pc cleaner
***** [ Scheduled Tasks ] *****
Task Found : ProgramRefresh-ATFST
Task Found : ProgramUpdateCheck
***** [ Shortcuts ] *****
***** [ Registry ] *****
Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=14077689 ... XX5VG02CS6
Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\APNDTX
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\pdfforge
Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\Search Settings
Key Found : HKCU\Software\AppDataLow\Software\Smartbar
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Bitberry
Key Found : HKCU\Software\Classes\iLivid.torrent
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\filescout
Key Found : HKCU\Software\FileTypeAssistant
Key Found : HKCU\Software\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKCU\Software\ilivid
Key Found : HKCU\Software\ilividmoviestoolbar181
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\iVIDI Plugin
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4D2BA467-3AD4-45D9-AA6D-DA4F4310C985}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5F52C651-A33D-45C3-A82D-514BEA5875D2}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9E646E93-E9FE-4B93-B6BC-B5224BE61D4E}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\PIP
Key Found : HKCU\Software\powerpack
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\SupHpUISoft
Key Found : HKCU\Software\UpdateStar
Key Found : HKCU\Software\USyndication
Key Found : HKCU\Software\usyndication.com
Key Found : HKLM\SOFTWARE\Classes\7Go Games.ScriptHostObject
Key Found : HKLM\SOFTWARE\Classes\7Go Games.ScriptHostObject.1
Key Found : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Found : HKLM\SOFTWARE\Classes\AppID\{685F23D9-FCFD-475C-B56A-362645945C5A}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Found : HKLM\SOFTWARE\Classes\iLivid.torrent
Key Found : HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Found : HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Found : HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Found : HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Found : HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Found : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject
Key Found : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DataMngr
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cflheckfmhopnialghigdlggahiomebp
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Key Found : HKLM\SOFTWARE\istartsurfSoftware
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1DAC034-9FD9-4C13-A388-D2E10E57707F}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}
Key Found : HKLM\SOFTWARE\microsoft\shared tools\msconfig\startupreg\PCSpeedUp
Key Found : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbar181CR
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trusted Software Assistant_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WindowsMangerProtect
Key Found : HKLM\SOFTWARE\PIP
Key Found : HKLM\SOFTWARE\Speedchecker Limited
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\Uniblue
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Value Found : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x86]
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://www.istartsurf.com/web/?type=ds&ts=1407 ... earchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.istartsurf.com/web/?type=ds&ts=1407 ... earchTerms}
-\\ Mozilla Firefox v32.0.3 (x86 cs)
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.BT_Stats.enc", "eyJsYXN0X2xvZyI6MTM2NDMyMTQ3NCwidXVpZCI6Nzc4NTk1MzMyODU4NDAsInNlcV9pZCI6Niwic3NiIjoxMzYzNTM5MTIxfQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FF19Solved", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FirstTime", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.FirstTimeFF3", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.PG_ENABLE", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.PG_ENABLE.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN17420652583231028&UM=1&q=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.UserID", "UN17420652583231028");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.addressBarTakeOverEnabledInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.autoDisableScopes", -1);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.browser.search.defaultthis.engineName", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.countryCode", "CZ");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.defaultSearch", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.enableFix404ByUser", "FALSE");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.enableSearchFromAddressBar", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.firstTimeDialogOpened", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundError", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundErrorByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixPageNotFoundErrorInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fixUrls", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.fullUserID", "UN17420652583231028.UP.20130712161855");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.homepageuserchanged", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installDate", "17/3/2013 17:46:41");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installType", "xpe");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installUsage", "2013-03-17T19:51:46.16269+03:00");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installUsageEarly", "2013-03-17T19:51:40.4373799+03:00");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.installerVersion", "1.3.6.5");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isCheckedStartAsHidden", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isFirstTimeToolbarLoading", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.isWelcomPage", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.keyword", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3289075&octid=CT3289075&SearchSource=15&CUI=UN17420652583231028&SSPV=&Lay=1&UM=\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.lastVersion", "10.20.0.513");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appStateReportTime.enc", "MTM2NDMwOTE0MDU3OQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appState_CouponBuddy.enc", "b24=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appState_PriceGong.enc", "b24=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsIm9wdGlvbnNEaWFsb2ciOnsiZGlzcGxheU5h[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6IjQzZmVjMDg1LWNkMzktNGQyZi05MDZhLTAyNTdkZjM2YzlhYiIsImRvbWFpbnMiOls[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_currentVersion.enc", "MS40LjQuNg==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_eventsCache.enc", "eyJjNWIwYWE2MS1jOTA1LTRmNzctYTU0YS04ODBiMjQ1Yjc0NjgiOnsidG9waWMiOiJzZW5kVXNhZ2UiLCJkYXRhIjpbIldlbGNvbWUiLCJWaWV3Il0sInVuaXF1ZUlkIjoiYzViMGFhNjEtYzkwNS00Z[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_first_time.enc", "MQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_gadgetOpen.enc", "MA==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_lastLoginTime.enc", "MTM2NDMwOTEzOTM2Ng==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIg[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_settings1.4.3.2.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_settings1.4.4.6.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcmllbmNlRW5hYmxlZEJ5RGVmYXVsd[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_userId.enc", "NDg1ZDYxZTItNjE4Yy00MTc3LTgyMTYtYmFjODk1MGEzYWIz");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.mam_gk_user_apps_selection.enc", "");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.migrateAppsAndComponents", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxps%3A%2F%2Fwww.google.cz%2F%3Fgws_rd%3Dcr%26ei%3D1p6wUuTJFMmL4gTi0IGoCQ%23q%3Dseznam\",\"EB_MAIN_FRAME_TITLE\":\"seznam%20-%20[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.openThankYouPage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.openUninstallPage", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.originalSearchAddressUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.revertSettingsEnabled", "FALSE");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.search.searchAppId", "130064539389933152");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.search.searchCount", "0");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchFromAddressBarEnabledByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchInNewTabEnabledByUser", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchInNewTabEnabledInHidden", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.searchSuggestEnabledByUser", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3289075\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://uTorrentControlv6.OurToolbar.com//xpi\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"uTorrentControl_v6 \"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_Configuration_lastUpdate", "1383234107957");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1363539108672");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_appsMetadata_lastUpdate", "1364236598900");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1363539108507");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1363539103379");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1363539108168");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_location_lastUpdate", "1373386860745");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.14.370.24_lastUpdate", "1363539108745");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.14.370.524_lastUpdate", "1364234334947");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.15.0.562_lastUpdate", "1369368840761");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.2.509_lastUpdate", "1373386861201");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.4.519_lastUpdate", "1375094193757");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.16.70.505_lastUpdate", "1379256403004");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_login_10.20.0.513_lastUpdate", "1383234108699");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1363539108387");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_searchAPI_lastUpdate", "1383234108195");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_serviceMap_lastUpdate", "1383234107879");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_toolbarContextMenu_lastUpdate", "1363539108296");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_toolbarSettings_lastUpdate", "1383234108082");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.serviceLayer_services_translation_lastUpdate", "1383234108154");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.settingsINI", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.shouldFirstTimeDialog", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.showToolbarPermission", "false");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.CTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.Uninstall", "0");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.homepage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.isHidden", true);
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.smartbar.toolbarName", "uTorrentControl_v6 ");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.startPage", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarBornServerTime", "17-3-2013");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarCurrentServerTime", "31-10-2013");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarDisabled", "true");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.toolbarLoginClientTime", "Sun Mar 17 2013 17:51:48 GMT+0100");
[ja7w1r9c.default] - Line Found : user_pref("CT3289075.url_history0001.enc", "aHR0cDovL3d3dy53YXR0c2VuZ2xpc2guY29tL2xldG5pLWphenlrb3ZlLXRhYm9yeS9wcmlobGFza3ktbmEtdGFib3IvNjU4MC1wcmltZXN0c2t5LXRhYm9yLXMtYW5nbGljdGlub3UtYmFrb3Ytbi1qaXpl[...]
[ja7w1r9c.default] - Line Found : user_pref("CT3289075_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1387306741621,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitHomepagesList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitSearchEngineList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.ConduitSearchUrlList", "");
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz[...]
[ja7w1r9c.default] - Line Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("browser.newtab.url", "hxxp://www.istartsurf.com/newtab/?type=nt&ts=1 ... XX5VG02CS6");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaultengine", "Ask.com");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaultthis.engineName", "uTorrentControl_v6 Customized Web Search");
[ja7w1r9c.default] - Line Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&CUI=UN17420652583231028&UM=1&SearchSource=3&q={searchTerms}");
[ja7w1r9c.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://www.istartsurf.com/?type=hp&ts=14077689 ... XX5VG02CS6");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.id", "\"13456c7f-d618-c528-8573-b234182f37b2\"");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.mzID", "93");
[ja7w1r9c.default] - Line Found : user_pref("extensions.7go@7go.com.uuid", "\"171fc5c0-220e-11e3-8099-0025901ef77c\"");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.admin", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.aflt", "3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.appId", "{685F23D9-FCFD-475C-B56A-362645945C5A}");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.autoRvrt", "false");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dfltLng", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dfltSrch", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.dnsErr", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.excTlbr", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.ffxUnstlRst", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hmpg", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hmpgUrl", "hxxp://search.ividi.org/?src=tbhp&id=58e1aba6000000000000001d6010cccc&affilt=3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.hpOld0", "about:home");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.id", "58e1aba6000000000000001d6010cccc");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.instlDay", "15997");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.instlRef", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.kw_url", "hxxp://search.ividi.org/?src=tbsp&id=58e1aba6000000000000001d6010cccc&affilt=3&q=");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.newTab", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.newTabUrl", "hxxp://search.ividi.org/?q={searchTerms}&src=tbnt&id=58e1aba6000000000000001d6010cccc&affilt=3");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.prdct", "ividi");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.prtnrId", "ividi");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.rvrt", "false");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.smplGrp", "none");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.srchPrvdr", "Search ");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.tlbrId", "base");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.tlbrSrchUrl", "hxxp://search.ividi.org/?src=tbsp&id=58e1aba6000000000000001d6010cccc&affilt=3&q=");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsn", "1.8.23.0");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsnTs", "1.8.23.014:39:25");
[ja7w1r9c.default] - Line Found : user_pref("extensions.ividi.vrsni", "1.8.23.0");
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si=[...]
[ja7w1r9c.default] - Line Found : user_pref("extensions.mywebsearch.prevSelectedEngine", "Google");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&p2=^UX^xdm007^YY^cz&si=CKiQjeeDtrQCFURY3godR[...]
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.enabled", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.hp.user.defined", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.initialized", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.contextKey", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.installDate", "2012122518");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerId", "^UX^xdm007^YY^cz");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.partnerSubId", "CKiQjeeDtrQCFURY3godRxsAbA");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.success", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.installation.toolbarId", "041ACE5B-510D-4FDB-AFEA-BDBB45E66115");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.lastActivePing", "1396709834189");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.defaultSearch", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.homePageEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.keywordEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.options.tabEnabled", true);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.searchHistory", "dlouhonovice||seznam.cz||||umgreifen||bazény baumax||bazény obi||mountfield bazény||vjera hensova||www.google.com||google.cz");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark._39Members_.weather.location", "10001");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[ja7w1r9c.default] - Line Found : user_pref("extensions.toolbar.mindspark.lastInstalled", "mapsgalaxy@mindspark.com");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.addressBarOwnerCTID", "CT3289075");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3289075&CUI=UN17420652583231028&UM=1&SearchSource=13");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3289075&SearchSource=2&CUI=UN17420652583231028&UM=1&q=,hxxp://search.conduit.com/ResultsExt.aspx?cti[...]
[ja7w1r9c.default] - Line Found : user_pref("smartbar.machineId", "VHN2ZWSJU7WJFM+6EMYAMQ2DCILOH4I22ZJ/HZHDBQHXC8AUAGWJPHMHRZMWSV3ZXCCTFM2TR3K+G1TH9RWRRW");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalHomepage", "hxxps://www.google.cz/");
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalSearchAddressUrl", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=041ACE5B-510D-4FDB-AFEA-BDBB45E66115&n=77ee8d96&ind=2012122518&p2=^UX^xdm007^YY^cz&si=[...]
[ja7w1r9c.default] - Line Found : user_pref("smartbar.originalSearchEngine", "Google");
-\\ Google Chrome v38.0.2125.122
-\\ Opera v25.0.1614.68
*************************
AdwCleaner[R0].txt - [306 octets] - [17/11/2014 15:41:00]
AdwCleaner[R1].txt - [306 octets] - [17/11/2014 15:43:21]
AdwCleaner[R2].txt - [38595 octets] - [17/11/2014 15:52:52]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [38656 octets] ##########
A nakonec log z zoek:
Zoek.exe v5.0.0.0 Updated 16-November-2014
Tool run by user on st 18.07.2007 at 1:05:47,48.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\user\Desktop\zoek.exe [Scan all users] [Script inserted]
==== Older Logs ======================
C:\zoek-results2014-11-17-154426.log 1303 bytes
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B9497038-4743-4322-89E0-89440634CE68} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_USERS\S-1-5-21-1161798421-1374263499-860267216-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{96F454EA-9D38-474F-B504-56193E00C1A5} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\prefs.js:
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
user.js not found
---- Lines Yawtix removed from prefs.js ----
user_pref("extensions.Yawtix.aul", "1407136410566");
user_pref("extensions.Yawtix.irl", true);
user_pref("extensions.Yawtix.is", "IM27lsCZ");
user_pref("extensions.Yawtix.ug", "5B4D3B00-DBDF-4A12-BD0F-40D1272FDAE9");
---- Lines foxlingo removed from prefs.js ----
user_pref("foxlingo.installed", true);
user_pref("foxlingo.usetoolbar", false);
user_pref("foxlingo.version", "1");
---- Lines {96F454EA-9D38-474F-B504-56193E00C1A5} modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST So
---- FireFox user.js and prefs.js backups ----
prefs_18.07.2007_0125_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Špidla Data Processing, s.r.o not found
C:\PROGRA~2\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted
C:\Users\user\AppData\LocalLow\uTorrentControl_v6 deleted
C:\Program Files\GUT260E.tmp deleted
C:\Program Files\GUM260D.tmp deleted
C:\Program Files\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\found.000 deleted
C:\Users\user\AppData\Roaming\CamStudio.Producer.Data.ini deleted
C:\Users\user\AppData\Roaming\CamStudio.Producer.ini deleted
C:\Users\user\AppData\Roaming\die.bat deleted
C:\Users\user\AppData\Roaming\apachesrvin.vbs deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\user\AppData\Local\CRE deleted
C:\Users\user\AppData\Local\cache deleted
C:\Windows\system32\config\systemprofile\AppData\Local\FileTypeAssistant deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Users\Public\Documents\AlawarWrapper deleted
C:\Users\user\Documents\Add-in Express deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\searchplugins\googlecustomsearch.xml deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\ilividmoviestoolbar181 deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\CT3289075 deleted
C:\Users\user\Desktop\Continue installation - Keygen Installer Installation.lnk deleted
C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\{d1dac034-9fd9-4c13-a388-d2e10e57707f} deleted
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5} deleted
"C:\Users\user\AppData\Local\{4C77CAB7-FD04-438A-A686-EAE3B14E36F8}" deleted
"C:\Users\user\AppData\Local\{93505646-2FA2-4D9F-949A-BD89F570EE0F}" deleted
"C:\Users\user\AppData\Roaming\pdfconverter" deleted
"C:\Users\user\AppData\Roaming\install" deleted
"C:\Users\user\AppData\Roaming\Samsung" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [09.09.2013 17:07]
==== Firefox Extensions ======================
ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- DoNotTrackMe: Online Privacy Protection - %ProfilePath%\extensions\donottrackplus@abine.com
- Ask New Tabs - %ProfilePath%\extensions\{2FD73609-F02D-3849-D765-5F8F93ECC348}
- iMacros for Firefox - %ProfilePath%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default
67D325B5AEB28E381B84E8DE1A90C7A8 - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll - Shockwave Flash
64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre1.7.0_45\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre1.7.0_45\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
F6D12679B9112358AC705A1308156F59 - C:\Users\user\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
C47920B4F36C19F97BD2EC19481387E5 - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll - Pando Web Plugin
F3B0E300AFC94E1A775A2D935A7D384F - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll - Shockwave for Director / Shockwave for Director
5B92CB0A3EEE50F6B9AE036B4F9B0F0C - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
0D80C49D9A4A3E096296C67BD015F614 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Photo Gallery
A843FC35574ECFD9E7A41C5505A9921B - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
D2377C9458EFEB094E38B8C874AA214C - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
==== Deleted Firefox Extensions ======================
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\ja7w1r9c.default\extensions\donottrackplus@abine.com deleted
==== Chromium Look ======================
==== Chromium Fix ======================
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.istartsurf.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mbmpjbkgemhgalmeiigcdljkccfcafoj_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_clients5.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_clients5.google.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_mail.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_blog.teesupport.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_blog.teesupport.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc.poradna.net_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pc.poradna.net_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_reklama2.viry.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_reklama2.viry.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure-us.imrworldwide.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure-us.imrworldwide.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bleepingcomputer.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bleepingcomputer.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.slunecnice.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.slunecnice.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.stalo-se.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.stalo-se.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.tomasstodola.com_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.tomasstodola.com_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.viry.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.viry.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zive.cz_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zive.cz_0.localstorage-journal deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_knohfebhibeknbfioecpdmdkjkjdnjnl_0.localstorage deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\opera_discover_0.localstorage deleted successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Local Storage\opera_startpage_0.localstorage deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\http_www.zive.cz_0 deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mbmpjbkgemhgalmeiigcdljkccfcafoj deleted successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{BD641314-9261-4934-AF7C-4622F42C2EDD}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BD641314-9261-4934-AF7C-4622F42C2EDD}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{97DB78A0-51AC-403D-99A8-2D4A35ADF5C1} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
==== Reset Google Chrome ======================
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{00EB810E-E56A-4308-A1E3-AD48DB08A3F8} deleted successfully
HKEY_LOCAL_MACHINE\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ilividmoviestoolbar181FF deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart PC Cleaner deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully
==== Empty IE Cache ======================
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\ja7w1r9c.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\user\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=1797 folders=466 153936598 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\user\AppData\Local\Temp will be emptied at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\user\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 18.07.2007 at 0:01:36,52 ======================
Re: IstartSurf
To je poradna sbirka
Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Možnost podpořit naše fórum https://platba.viry.cz/payment/
-
Davidas1
Re: IstartSurf
Tady je log z MBAM:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 17.11.2014
Scan Time: 18:01:31
Logfile: malwarwbytes-original.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.16.03
Rootkit Database: v2014.11.12.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: user
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 543616
Time Elapsed: 1 hr, 42 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 4
PUP.Optional.uTorrentControl.A, HKLM\SOFTWARE\uTorrentControl_v6, , [353eb488f884ae880624a8bca261e719],
PUP.Optional.Ividi.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\iVIDI.org, , [77fc340826561422419ac9a8b251d62a],
PUP.Optional.uTorrentControl.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\uTorrentControl_v6, , [f18282ba057721156ebd5a0a9370659b],
PUP.Optional.FastStart.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, , [20532d0ffb81ce6842d758e709faff01],
Registry Values: 1
PUP.Optional.FastStart.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [20532d0ffb81ce6842d758e709faff01]
Registry Data: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[8ce74def186479bd5292bf8a28dd03fd]
Folders: 0
(No malicious items detected)
Files: 31
PUP.Optional.Somoto.A, C:\Users\user\Desktop\ClickHeretoDownloadSetup-N1HBy7YLM.exe, , [acc766d6463613237be67d27e120d927],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth156.dll.vir, , [690aef4d413b06307d778e36e61b837d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth181.dll.vir, , [91e2a894fa8200364da70aba0df436ca],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth182.dll.vir, , [43304af273097fb7cc283391b44d24dc],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx156.dll.vir, , [6d069ca02b5145f1b63e972d68992ed2],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx181.dll.vir, , [cea572cab7c5e551df1530941ae79d63],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx182.dll.vir, , [f38089b31b6193a38d67a91b798841bf],
PUP.Optional.Conduit, C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir, , [393a93a9700c73c38136e649ea16827e],
PUP.Optional.Ilivid, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\Uninstall.exe.vir, , [84ef03392854cc6ad5afd111748d9769],
PUP.Optional.MoviesToolBar.A, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\FF\uninstall.exe.vir, , [b0c365d794e803332420a6cc9f662dd3],
PUP.Optional.MoviesToolBar.A, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\GC\uninstall.exe.vir, , [9bd879c32953b08670d4e88ac73e20e0],
PUP.Optional.MyPCBackup.A, C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\MyPC Backup.exe.vir, , [472cd4680f6d71c5aea7bb2335ccd12f],
PUP.Optional.MyPCBackup.A, C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\Service Start.exe.vir, , [155e98a4225a01359cb905d950b16f91],
PUP.Optional.SearchProtect, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\Loader64.exe.vir, , [81f21f1d5c2084b28700c51939c841bf],
PUP.Optional.IEPluginService.A, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\RSHP.exe.vir, , [77fc58e4f18b94a2e5934b37b44d857b],
PUP.Optional.ELEX, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupIePluginServiceUpdate.exe.vir, , [561d2517483496a00b2a7a3fd32e768a],
PUP.Optional.SupTab.A, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir, , [6d065fdd7309eb4b2261979ef7097a86],
PUP.Optional.ELEX, C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir, , [97dcc07cc0bc42f4999c8831728f7d83],
PUP.Optional.WindowsProtectManger.A, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, , [551e1a224d2f2412129ba5161de442be],
PUP.Optional.Conduit.A, C:\AdwCleaner\Quarantine\C\users\user\AppData\Local\Conduit\CT3289075\uTorrentControl_v6AutoUpdateHelper.exe.vir, , [680b93a92458b3831f51d44a649cfe02],
RiskWare.Tool.HCK, C:\Program Files\Sony\Vegas Pro 11.0\Keygen.exe, , [185b6ad2017b0b2be0f26fe1e71bb947],
BitcoinMiner, C:\Windows\inf\mspuinaep\mspuinaep.exe, , [92e1ca721b619d993336d442986955ab],
BitcoinMiner, C:\Windows\inf\msyvjews\msyvjews.exe, , [a3d0d765afcda3935712e630a0613cc4],
PUP.Optional.Spigot.A, C:\Windows\Installer\MSIABBB.tmp, , [e29170cc3943a6906391daea36cbe41c],
PUP.Optional.Spigot.A, C:\Windows\Installer\85457e.msi, , [244fba8285f787afd91bb01426db6f91],
Trojan.Agent.W, C:\Windows\Setup\SCRIPTS\Windows7Loader.exe, , [97dc77c579030b2b60ed2cd439cce31d],
Adware.InstallBrain, D:\Davidek\PdfSpeedSetup.exe, , [9dd6122a0f6d66d049f0c65ba75aab55],
Adware.Vomba, D:\Zaloha\Programy_Instalace\daemon410-x86.exe, , [f67d87b51a623afc3506e46e38cdb848],
PUP.Optional.IStartSurf.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\istartsurf.xml, , [ec87201c4e2e0b2bae438aba2ed533cd],
Stolen.Data, C:\Users\user\AppData\Roaming\userv1.18.0 - Trial versionlog.dat, , [b4bf4fed14680630a4a26cba956f2ed2],
Malware.Trace, C:\Windows\inf\ntvdm.inf, , [2053013b1a6278be07e44642669e1fe1],
Physical Sectors: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 17.11.2014
Scan Time: 18:01:31
Logfile: malwarwbytes-original.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.16.03
Rootkit Database: v2014.11.12.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: user
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 543616
Time Elapsed: 1 hr, 42 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 4
PUP.Optional.uTorrentControl.A, HKLM\SOFTWARE\uTorrentControl_v6, , [353eb488f884ae880624a8bca261e719],
PUP.Optional.Ividi.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\iVIDI.org, , [77fc340826561422419ac9a8b251d62a],
PUP.Optional.uTorrentControl.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\uTorrentControl_v6, , [f18282ba057721156ebd5a0a9370659b],
PUP.Optional.FastStart.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, , [20532d0ffb81ce6842d758e709faff01],
Registry Values: 1
PUP.Optional.FastStart.A, HKU\S-1-5-21-1161798421-1374263499-860267216-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [20532d0ffb81ce6842d758e709faff01]
Registry Data: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[8ce74def186479bd5292bf8a28dd03fd]
Folders: 0
(No malicious items detected)
Files: 31
PUP.Optional.Somoto.A, C:\Users\user\Desktop\ClickHeretoDownloadSetup-N1HBy7YLM.exe, , [acc766d6463613237be67d27e120d927],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth156.dll.vir, , [690aef4d413b06307d778e36e61b837d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth181.dll.vir, , [91e2a894fa8200364da70aba0df436ca],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wth182.dll.vir, , [43304af273097fb7cc283391b44d24dc],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx156.dll.vir, , [6d069ca02b5145f1b63e972d68992ed2],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx181.dll.vir, , [cea572cab7c5e551df1530941ae79d63],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files\Common Files\Spigot\Search Settings\wthx182.dll.vir, , [f38089b31b6193a38d67a91b798841bf],
PUP.Optional.Conduit, C:\AdwCleaner\Quarantine\C\Program Files\Conduit\Community Alerts\Alert.dll.vir, , [393a93a9700c73c38136e649ea16827e],
PUP.Optional.Ilivid, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\Uninstall.exe.vir, , [84ef03392854cc6ad5afd111748d9769],
PUP.Optional.MoviesToolBar.A, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\FF\uninstall.exe.vir, , [b0c365d794e803332420a6cc9f662dd3],
PUP.Optional.MoviesToolBar.A, C:\AdwCleaner\Quarantine\C\Program Files\Movies Toolbar\Datamngr\SRTOOL~1\GC\uninstall.exe.vir, , [9bd879c32953b08670d4e88ac73e20e0],
PUP.Optional.MyPCBackup.A, C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\MyPC Backup.exe.vir, , [472cd4680f6d71c5aea7bb2335ccd12f],
PUP.Optional.MyPCBackup.A, C:\AdwCleaner\Quarantine\C\Program Files\MyPC Backup\Service Start.exe.vir, , [155e98a4225a01359cb905d950b16f91],
PUP.Optional.SearchProtect, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\Loader64.exe.vir, , [81f21f1d5c2084b28700c51939c841bf],
PUP.Optional.IEPluginService.A, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\RSHP.exe.vir, , [77fc58e4f18b94a2e5934b37b44d857b],
PUP.Optional.ELEX, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupIePluginServiceUpdate.exe.vir, , [561d2517483496a00b2a7a3fd32e768a],
PUP.Optional.SupTab.A, C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir, , [6d065fdd7309eb4b2261979ef7097a86],
PUP.Optional.ELEX, C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir, , [97dcc07cc0bc42f4999c8831728f7d83],
PUP.Optional.WindowsProtectManger.A, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, , [551e1a224d2f2412129ba5161de442be],
PUP.Optional.Conduit.A, C:\AdwCleaner\Quarantine\C\users\user\AppData\Local\Conduit\CT3289075\uTorrentControl_v6AutoUpdateHelper.exe.vir, , [680b93a92458b3831f51d44a649cfe02],
RiskWare.Tool.HCK, C:\Program Files\Sony\Vegas Pro 11.0\Keygen.exe, , [185b6ad2017b0b2be0f26fe1e71bb947],
BitcoinMiner, C:\Windows\inf\mspuinaep\mspuinaep.exe, , [92e1ca721b619d993336d442986955ab],
BitcoinMiner, C:\Windows\inf\msyvjews\msyvjews.exe, , [a3d0d765afcda3935712e630a0613cc4],
PUP.Optional.Spigot.A, C:\Windows\Installer\MSIABBB.tmp, , [e29170cc3943a6906391daea36cbe41c],
PUP.Optional.Spigot.A, C:\Windows\Installer\85457e.msi, , [244fba8285f787afd91bb01426db6f91],
Trojan.Agent.W, C:\Windows\Setup\SCRIPTS\Windows7Loader.exe, , [97dc77c579030b2b60ed2cd439cce31d],
Adware.InstallBrain, D:\Davidek\PdfSpeedSetup.exe, , [9dd6122a0f6d66d049f0c65ba75aab55],
Adware.Vomba, D:\Zaloha\Programy_Instalace\daemon410-x86.exe, , [f67d87b51a623afc3506e46e38cdb848],
PUP.Optional.IStartSurf.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\istartsurf.xml, , [ec87201c4e2e0b2bae438aba2ed533cd],
Stolen.Data, C:\Users\user\AppData\Roaming\userv1.18.0 - Trial versionlog.dat, , [b4bf4fed14680630a4a26cba956f2ed2],
Malware.Trace, C:\Windows\inf\ntvdm.inf, , [2053013b1a6278be07e44642669e1fe1],
Physical Sectors: 0
(No malicious items detected)
(end)
Re: IstartSurf
Možnost podpořit naše fórum https://platba.viry.cz/payment/

Přispějete na provoz fóra?