zde je adv:
# AdwCleaner v4.105 - Report created 19/12/2014 at 12:19:54
# Updated 08/12/2014 by Xplode
# Database : 2014-12-16.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Petr Nahodil - PETR-LENOVO
# Running from : C:\Users\Petr Nahodil\Downloads\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : WindowsMangerProtect
Service Deleted : Orbiter
Service Deleted : trntv
Service Deleted : IHProtect Service
[#] Service Deleted : Update Reverse Page
[#] Service Deleted : Util Reverse Page
Service Deleted : {ced0cd5d-d90d-4de5-8a7e-4196208faea0}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\Program Files (x86)\ORBTR
[!] Folder Deleted : C:\Program Files (x86)\Reverse Page
Folder Deleted : C:\Users\PETRNA~1\AppData\Local\Temp\Reverse Page
Folder Deleted : C:\Users\Petr Nahodil\AppData\Local\SearchProtect
Folder Deleted : C:\Users\Petr Nahodil\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Petr Nahodil\AppData\Roaming\TornTV.com
Folder Deleted : C:\Users\Petr Nahodil\AppData\Roaming\RHEng
Folder Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
File Deleted : C:\windows\System32\drivers\{ced0cd5d-d90d-4de5-8a7e-4196208faea0}Gw64.sys
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TornTvDownloader.lnk
File Deleted : C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage-journal
File Deleted : C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.best-deals-products.com_0.localstorage-journal
File Deleted : C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.best-deals-products.com_0.localstorage-journal
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxps_www.best-deals-products.com_0.localstorage-journal
File Deleted : C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.best-deals-products.com_0.localstorage
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\pokki
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Torntv Downloader]
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Key Deleted : HKCU\Software\Classes\Directory\shell\pokki
Key Deleted : HKCU\Software\Classes\Drive\shell\pokki
Key Deleted : HKCU\Software\Classes\lnkfile\shell\pokki
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update Reverse Page
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util Reverse Page
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83dc36e5-db3f-461a-8fbc-245e44000b1f}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4c970696-3e8e-40a5-9f15-d64b7cd6dac3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83dc36e5-db3f-461a-8fbc-245e44000b1f}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\Pokki
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Reverse Page
Key Deleted : HKLM\SOFTWARE\omiga-plusSoftware
Key Deleted : HKLM\SOFTWARE\SearchProtect
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\ORBTR
Key Deleted : HKLM\SOFTWARE\Reverse Page
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : [x64] HKLM\SOFTWARE\TornTv Downloader
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reverse Page
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Google Chrome v39.0.2171.95
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
-\\ Opera v26.0.1656.60
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1418926239&from=ild&uid=LITEONITXLCS-256M6S_S45N7172Z1ZSEA037577&q={searchTerms}
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : aaipilfmheplbcghignccoiiebekkdhe
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : elchiiiejkobdbblfejjkbphbddgmljf
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ffhfoagmjcnkolneahbpagjcjjaeofbg
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : hjghiofiijcepdnocbgefbdlbckjfheg
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : iklgpchfbohgmghgfagediakopecfmbm
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : kfgaibfbmkjgmimhbbaikfnpkkjkpoan
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : lmnbobhffedhdhfpcjkjphcfpeeiocdn
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : kjpifmjicccpbkfjdkehimhgklfkbanh
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : hoidflomjnnnbiemmkjdjkkialmhbago
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ekpibplnnkfdcafdpoekhoffegcajene
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ipljmghelflfikejmgkmlmpjmehfjodc
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : ejddjnilmdncjilbfjgameihlklfpohp
[C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\preferences] - Deleted [Extension] : eagomcfjiefffhpaejnlpjccikpipdoe
*************************
AdwCleaner[R0].txt - [14678 octets] - [19/12/2014 12:14:11]
AdwCleaner[S0].txt - [13651 octets] - [19/12/2014 12:19:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13712 octets] ##########
a zde zoek:
Zoek.exe v5.0.0.0 Updated 19-December-2014
Tool run by Petr Nahodil on p 19. 12. 2014 at 12:22:53,93.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Petr Nahodil\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
19. 12. 2014 12:23:47 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\New Folder deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\regid.1986-12.com.adobe deleted successfully
C:\Users\Petr Nahodil\AppData\Local\WMTools Downloaded Files deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\OperaStable\shell\open\command]
@="C:\\Program Files (x86)\\Opera\\Launcher.exe"
==== Deleting Files \ Folders ======================
C:\windows\sysWoW64\config\systemprofile\.android deleted
C:\PROGRA~2\STab deleted
C:\Users\Public\Pokki deleted
C:\PROGRA~3\IHProtectUpDate deleted
C:\PROGRA~3\Pokki deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Default\AppData\Local\Pokki deleted
C:\Users\Petr Nahodil\AppData\Local\Pokki deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk deleted
C:\Users\Petr Nahodil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk deleted
C:\Users\Petr Nahodil\Downloads\SoftonicDownloader_for_fraps.exe deleted
C:\Users\Petr Nahodil\Downloads\SoftonicDownloader_for_windows-movie-maker-2012.exe deleted
C:\windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb deleted
C:\Users\Petr Nahodil\Desktop\Torntv Downloader.lnk deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [14. 12. 2014 23:08]
==== Chromium Look ======================
Google Chrome Version: 39.0.2171.95 (Could not determine latest Stable Version)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14. 12. 2014 23:08]
==== Chromium Fix ======================
C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.best-deals-products.com_0.localstorage deleted successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_windows-movie-maker-2012.en.softonic.com_0.localstorage deleted successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_windows-movie-maker-2012.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_windows-movie-maker.cs.softonic.com_0.localstorage deleted successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_windows-movie-maker.cs.softonic.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com"
"Default_Page_URL"="
http://www.google.com"
"Search Page"="
https://www.google.com/search?trackid=s ... earchTerms}"
"Search Bar"="
https://www.google.com/?trackid=sp-006"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com"
"Search Page"="
http://www.google.com"
"Default_Page_URL"="
http://www.google.com"
"Default_Search_URL"="
http://www.google.com"
"Search Bar"="
https://www.google.com/?trackid=sp-006"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.google.com"
"Search Page"="
http://www.google.com"
"Default_Page_URL"="
http://www.google.com"
"Default_Search_URL"="
http://www.google.com"
"Search Bar"="
https://www.google.com/?trackid=sp-006"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="
http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="
http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="
http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="
http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Page_URL"="
http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="
https://www.google.com/search?trackid=s ... earchTerms}"
{F8A12884-DA69-4567-B631-BE99E0559E5A} Unknown Url="Not_Found"
==== Reset Google Chrome ======================
C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Web Data will be reset at reboot
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2085583770-3091255581-2521110835-1001\Software\Microsoft\Internet Explorer\SearchScopes\{F8A12884-DA69-4567-B631-BE99E0559E5A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\EO9K7J9K will be deleted at reboot
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\ORW1Q3NW will be deleted at reboot
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\Y83R8V1O will be deleted at reboot
C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\YWC4C745 will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache will be emptied at reboot
C:\Users\Petr Nahodil\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=9288 folders=243 550035734 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Petr Nahodil\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\PETRNA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Web Data" not found
"C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache\data_0" deleted
"C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache\data_1" deleted
"C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache\data_2" deleted
"C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache\data_3" deleted
"C:\Users\Petr Nahodil\AppData\Local\Opera Software\Opera Stable\Cache\index" deleted
"C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\https_www.best-deals-products.com_0.localstorage" not deleted
"C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.best-deals-products.com_0.localstorage" not deleted
"C:\Users\Petr Nahodil\AppData\Roaming\Opera Software\Opera Stable\Local Storage\http_www.best-deals-products.com_0.localstorage-journal" not deleted
"C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\EO9K7J9K" not found
"C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\ORW1Q3NW" not found
"C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\Y83R8V1O" not found
"C:\Users\Petr Nahodil\AppData\Local\Microsoft\Windows\INetCache\IE\YWC4C745" not found
==== EOF on p 19. 12. 2014 at 12:45:35,97 ======================