Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by Vojtěch at 2015-03-23 11:54:28 Run:1
Running from C:\Users\Vojtěch\Desktop
Loaded Profiles: Vojtěch (Available profiles: UpdatusUser & Vojtěch)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2015-01-24] (RealNetworks, Inc.)
HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [560192 2014-10-29] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-11-11] (Geek Software GmbH)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [Spotify Web Helper] => C:\Users\Vojtěch\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1959992 2015-03-09] (Spotify Ltd)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\Run: [Spotify] => C:\Users\Vojtěch\AppData\Roaming\Spotify\Spotify.exe [6611512 2015-03-09] (Spotify Ltd)
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\MountPoints2: {7b0a68b6-bde8-11e4-be9f-e006e6bf2c39} - "G:\Startme.exe"
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\...\MountPoints2: {ed59d548-44f1-11e4-be87-e006e6bf2c39} - "G:\Startme.exe"
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => No File
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo13.msn.com
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
FF Extension: No Name - C:\Users\Vojtěch\AppData\Roaming\Mozilla\Firefox\Profiles\Tx1cA8GF.default\extensions\
abs@avira.com [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] -
https://clients2.google.com/service/update2/crx
015-03-23 11:14 - 2015-03-23 11:14 - 00023619 _____ () C:\Users\Vojtěch\Desktop\FRST.txt
2015-03-22 18:05 - 2015-03-22 18:05 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-03-22 18:03 - 2015-03-22 17:51 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2015-03-22 17:52 - 2015-03-22 18:06 - 00009660 _____ () C:\zoek-results.log
2015-03-22 17:51 - 2015-03-22 18:02 - 00000000 ____D () C:\zoek_backup
2015-03-22 17:50 - 2015-03-22 17:50 - 01305600 _____ () C:\Users\Vojtěch\Desktop\zoek.exe
2015-03-21 10:02 - 2015-03-21 10:02 - 02171392 _____ () C:\Users\Vojtěch\Desktop\adwcleaner_4.112.exe
2015-03-20 22:44 - 2015-03-20 22:45 - 00112640 _____ (forum.viry.cz) C:\Users\Vojtěch\Desktop\FRSTLauncher.exe
2015-03-20 13:39 - 2015-03-20 13:39 - 00000000 ____D () C:\Program Files (x86)\Express Find
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RealDownloader => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\PDFPrint => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Spotify Web Helper => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\HP Officejet Pro 8600 (NET) => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Sony PC Companion => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Spotify => value deleted successfully.
"HKU\S-1-5-21-3065073901-2688806363-962121247-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b0a68b6-bde8-11e4-be9f-e006e6bf2c39}" => Key deleted successfully.
HKCR\CLSID\{7b0a68b6-bde8-11e4-be9f-e006e6bf2c39} => Key not found.
"HKU\S-1-5-21-3065073901-2688806363-962121247-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ed59d548-44f1-11e4-be87-e006e6bf2c39}" => Key deleted successfully.
HKCR\CLSID\{ed59d548-44f1-11e4-be87-e006e6bf2c39} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp" => Key deleted successfully.
HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending" => Key deleted successfully.
HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot" => Key deleted successfully.
HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared" => Key deleted successfully.
HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51} => Key not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => value deleted successfully.
HKU\S-1-5-21-3065073901-2688806363-962121247-1002\Software\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}" => Key deleted successfully.
"HKCR\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}" => Key deleted successfully.
"HKCR\CLSID\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{553891B7-A0D5-4526-BE18-D3CE461D6310} => value deleted successfully.
"HKCR\CLSID\{553891B7-A0D5-4526-BE18-D3CE461D6310}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{553891B7-A0D5-4526-BE18-D3CE461D6310} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{553891B7-A0D5-4526-BE18-D3CE461D6310}" => Key deleted successfully.
C:\Users\Vojtěch\AppData\Roaming\Mozilla\Firefox\Profiles\Tx1cA8GF.default\extensions\
abs@avira.com not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk" => Key deleted successfully.
015-03-23 11:14 - 2015-03-23 11:14 - 00023619 _____ () C:\Users\Vojtěch\Desktop\FRST.txt => Error: No automatic fix found for this entry.
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Vojtěch\Desktop\zoek.exe => Moved successfully.
C:\Users\Vojtěch\Desktop\adwcleaner_4.112.exe => Moved successfully.
C:\Users\Vojtěch\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Program Files (x86)\Express Find => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\DriverToolkit Autorun.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => Moved successfully.
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.
EmptyTemp: => Removed 747.9 MB temporary data.
The system needed a reboot.
==== End of Fixlog 11:55:21 ====