potvury v ntb
Napsal: 23 bře 2015 22:46
Dobry vecer,
dostal se mi do rukou notebook, ktery byl radne zavirovany, prevazne v adresari appdata a pak jsem to projel jeste adwcleanerem a mbam, posledni jmenovany jiz nic nenasel. Ted k problemu, po tom vsem je ntb porad zpomaleny. Jiz jsem vypnul co se da po spusteni, probral sluzby, vycistil ccleanerem, zkontroloval disk jestli neni poskozeny a vypnul aero. Musi tam jeste nekde neco byt vnorene, jinak fakt uz nevim.
Tady je log z FRST:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Jarda at 2015-03-23 22:33:17
Running from C:\Users\Jarda\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
BatteryBar (remove only) (HKLM\...\BatteryBar) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CyberLink PowerDVD 10 (HKLM\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.1705 - CyberLink Corp.)
CyberLink PowerDVD 10.0.1516.51 - odinstalovat češtinu (HKLM\...\CyberLink PowerDVD 10.0.1516.51) (Version: - Michellin & Pavlík)
ESET Smart Security (HKLM\...\{A68ED22D-17E8-4B1C-A32F-12177796BA61}) (Version: 8.0.304.1 - ESET, spol s r. o.)
Google Drive (HKLM\...\{6C36881B-0E51-4231-9D02-BF2149664D34}) (Version: 1.20.8672.3137 - Google, Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Java 7 Update 76 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217076FF}) (Version: 7.0.760 - Oracle)
KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.9.1.132 - PandoraTV)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
ModelPrint 1.0.52 (HKLM\...\ModelPrint 1.0.52) (Version: 1.0.52 - )
Mozilla Firefox 36.0.4 (x86 cs) (HKLM\...\Mozilla Firefox 36.0.4 (x86 cs)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML4 Parser (HKLM\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.9 - Frank Heindörfer, Philip Chinery)
pdfforge Toolbar v1.1.2 (HKLM\...\{5791B7D3-8B34-4218-9750-6A8E45D0AD32}) (Version: 1.1.2 - Spigot, Inc.) <==== ATTENTION
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
STORMWARE PDF Printer 10.1.0.1871 (HKLM\...\STORMWARE PDF Printer_is1) (Version: 10.1.0.1871 - STORMWARE)
STORMWARE POHODA CZ Standard MLP (HKLM\...\{21E61A26-B4FC-4366-B914-E1C67A505784}) (Version: 10800.192 - STORMWARE)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 7.50a - Ghisler Software GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{052253BF-F1FF-4686-B231-8D1904DEED68}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{0F81C552-68AD-4AAB-99D2-26F7F72A423C}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Commmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1B72D1C3-A1B3-4C87-9552-894CFF74051F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1BC0C7E7-0ADF-4FCE-9FBD-70B2DBC3BD48}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameMdl.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1E1C74D3-EF64-4F13-B631-DFDCEE4572FD}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Loginmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1FD9E587-43E1-4F1F-A41F-A6E8B93A5546}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{2D0235FC-1701-4F1C-B36C-84CD8813EDB5}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{31DC369C-75C3-4D8B-9C2D-0B10BF77BA0F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{343ADE39-3C61-421B-93CB-19C44D33ED9B}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{47231DCA-F7A4-4696-B836-B2430D451226}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Imagemgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{4AC4E235-EB53-4942-B113-931D66A470B8}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameSelectorMdl.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{50021F2A-9C64-4766-A697-84E366A407B1}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{50632C37-EDD8-4B8F-A32B-8E280D942A8E}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{51B894AD-B2D5-48F6-B1D1-C1F0CF849587}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{553E32D1-AAF3-406A-B19E-E575829EC651}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{648326CD-6F37-4A8F-BF14-E2BAD67AAAA8}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{693566bc-21f8-401e-8d42-e2c5ce50dacc}\localserver32 -> C:\Users\Jarda\AppData\Local\Temp\{d5641912-e47a-429c-879e-cfe13eac7a13}\IDriver.NonElevated.exe No (the data entry has 4 more characters).
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{6BB1EAF0-7572-4166-9DF4-2A817F5FCD83}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{6F80F85C-FC5C-4C7E-B7ED-9ECCECC7CF57}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Configmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{72A62965-EF25-42E0-97CE-7A2D69BF28C0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8A0F754D-9636-4771-A1A6-8A1126E03345}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8A73CF97-446B-46AD-964C-2C3400CAA60F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8B48847D-052F-4153-93B8-7223BFF1C406}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Commmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8B5F91E9-0032-4560-93B0-4539497C5366}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{941D2E9A-D724-4FB5-94D5-775B70E8C408}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{97637B78-01D0-4A40-A842-68774AA416BB}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{987585FA-DD0C-4E8B-8FC2-89B1181CA701}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{9A5A84A0-2E60-47D1-8C75-278A8D0F41FF}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{9E8F05AF-C18E-4A72-8743-A479EFD255E6}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A16CA865-CD74-46EC-9432-74579FD657A0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A2DF38B5-93D0-44D6-8130-AA80F351F852}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Timemgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A70E086C-1477-4B0C-808A-94EF8271ED39}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Resourcemgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A7674421-DB75-4081-B0FE-2B378F1FFAEB}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameMdl.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ACAB158F-423F-4D59-BEDD-15C9E0CC2DD1}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B10A3751-CC13-4A25-875B-EEC84674C6C0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Soundmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B1267A8A-D143-41F7-A655-5765A8464796}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B6C64A50-7BB8-441B-AE31-C4366C84BF00}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B8217B92-8FDD-4A74-9417-B77BD74F62B7}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{BD75936F-2B69-477E-9E9A-218FFAF35F49}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{BE742811-02F4-4D7E-87C1-886909462A16}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Modulemgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D2E87C0B-C06A-4E69-8A41-0AC3117505B4}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D4A86438-A95B-487D-8B1D-1E67B2A0F379}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\DownloadMgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D7B3EAC0-36D9-459E-AC96-3A88309FDDCC}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E65E6AAE-9169-4625-B98D-EB903E707116}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E6BFA606-59F2-4CD6-89C8-DAED6D789027}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E9AC37A2-E79C-4CA3-A6A8-1884BF9A7852}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{EAD67B06-459C-48B9-90C1-5F2F34D4F83F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ECA7C134-E84B-4E6B-A3E2-355FCB853766}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ED0BD0F4-ECAC-41D2-BD28-0ABFB129F40C}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\VersionMgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{F0349E13-BD03-4073-BA25-6B2610C0750D}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{F53E4C9E-703C-41f3-8F69-C7E3D277594B}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{FD995983-DC2B-4B97-B3FE-E9534AA1A769}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{FE0AA82B-B32A-4D54-BA97-918D2A9F6E70}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
==================== Restore Points =========================
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0149987B-2C2D-4941-848C-E999C7496C02} - System32\Tasks\{D5A08C13-DAF9-4305-A17F-1CC81566FEFC} => pcalua.exe -a G:\setup.exe -d G:\
Task: {03ED2C1B-E46E-4DE5-B1BD-61F97D352BA6} - System32\Tasks\{B69A4323-FD1D-4B76-8412-759752B923CC} => pcalua.exe -a G:\Installer.exe -d G:\
Task: {046A7CD2-2F9E-4595-B321-A65C03ACDE52} - System32\Tasks\{F6826F31-F3CC-4BD2-8FB9-98F054DCAFF9} => pcalua.exe -a "C:\Program Files\Common Files\CADS Shared\StructuralDesigners\SteelMemberDesigner\Uninstall SMD.exe" -c C:\Program Files\Common Files\CADS Shared\StructuralDesigners\SteelMemberDesigner\Install.log
Task: {0745BB18-569D-43FD-8243-6C9380AB0252} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {0F025A5E-FA56-4BD1-A5DC-049A963E13BC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
Task: {0FA489BC-4407-49B5-953B-7AF80A0A3AB6} - System32\Tasks\{3151EBA5-BC2F-4EAE-BD04-E002892505D4} => C:\Program Files\Skype\Phone\Skype.exe
Task: {1123A1E1-A512-40F4-B438-284550483057} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-23] (Adobe Systems Incorporated)
Task: {18E4DCD7-61BC-4A86-927F-49F4C534D943} - System32\Tasks\{7C9A15EB-DDFE-4842-907B-E0811B66206D} => pcalua.exe -a D:\hry\steam\steam.exe -c steam://uninstall/34200
Task: {22C585C2-C4B2-42A3-B819-388C5CF0808E} - System32\Tasks\{1DD1D994-D800-4B08-9F53-A3C14D8C4136} => pcalua.exe -a C:\Users\Jarda\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=kmp <==== ATTENTION
Task: {2382DBB0-DF9F-434F-98EB-BC05AAE6E1FF} - System32\Tasks\{C068C1CF-590E-4CFF-99B8-4FE2237B7895} => pcalua.exe -a "D:\hry\Warcraft III\w3_battle124bfix2\w3_battle124bfix2.exe" -d "D:\hry\Warcraft III\w3_battle124bfix2"
Task: {39D2CC2A-653E-47A7-BF55-3F69388F9E02} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {3BBF137E-A8C3-4160-AF21-BD4AC4C06097} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {3DE5B956-522F-4F2D-ADCD-CDB8B0EF67D4} - System32\Tasks\{8E132A3C-514B-4098-8F65-900F6C109F7F} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/cs/a ... rogressBar
Task: {5156D418-52AE-407D-94F4-61F2192EEA8F} - System32\Tasks\{7C74393A-60C9-43B2-9AEB-0861D91C2830} => pcalua.exe -a C:\Users\Jarda\Desktop\modem\Axesstel_Setup.exe -d C:\Users\Jarda\Desktop\modem
Task: {5AB1A5AE-012B-48CA-BF9A-D547623D4EDC} - System32\Tasks\{AAEAB2D3-9384-4D1A-A8B0-F05D5A11A446} => pcalua.exe -a D:\hry\w3_battle124bfix2\w3_battle124bfix2.exe -d D:\hry\w3_battle124bfix2
Task: {5DF48A6B-6E8D-4119-A20A-D266D35B6998} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {5EDDAC18-82CF-437E-9D7B-1F2FD93D23AC} - System32\Tasks\{693BC7DC-C27F-4B3A-98AA-4942A618693F} => pcalua.exe -a "C:\Program Files\ModelPrint\1.0.52\uninstall.bat"
Task: {76DAE199-868B-41E2-ADE2-6BA4B788045E} - System32\Tasks\{FAEE0FF3-DD9B-42C2-B79B-6235F2329D60} => pcalua.exe -a G:\setup.exe -d G:\
Task: {771A4A4A-F53F-40C6-85A6-F622A8A19626} - System32\Tasks\{1C2E7BC4-24F7-4777-A1C6-4162AA6BE30A} => pcalua.exe -a F:\AUTORUN.EXE -d F:\
Task: {888BF0F9-B878-4D91-BB5B-839060BAFE52} - System32\Tasks\{8E20E725-3F61-4868-AD80-C85558789323} => pcalua.exe -a G:\setup.exe -d G:\
Task: {ACE47E23-1BA6-4CDF-A467-7635DA199FDE} - System32\Tasks\{18E89797-CAA7-43F9-81B6-B878762E0086} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{6DBAF277-66A6-4DA9-8E01-AA549CED1DDB}\setup.exe" -c -runfromtemp -l0x0405 -removeonly
Task: {CD743E61-14B3-48CC-AD12-6D425F13D21C} - System32\Tasks\{307DDD9B-C03E-418E-AF28-245397E5F407} => pcalua.exe -a "C:\Program Files\AutoCAD 2010\Setup\Setup.exe" -c /P {5783F2D7-8001-0405-0002-0060B0CE6BBA} /M ACAD /language cs-CZ
Task: {CF4DF457-A4D7-4C22-92F7-1247BF8FFF7C} - System32\Tasks\{F2C1836E-D463-4432-AB93-5521B96CAF91} => pcalua.exe -a "D:\prace\škola\Projekt 1\Geo_5.exe" -d "D:\prace\škola\Projekt 1"
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2010-02-05 08:38 - 2001-10-28 16:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2010-02-04 07:41 - 2008-08-29 10:55 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll
2010-02-04 07:41 - 2008-09-03 15:28 - 00319488 _____ () C:\Program Files\WinRAR\rarlng.dll
2014-03-23 23:29 - 2014-03-23 23:29 - 00818176 _____ () C:\CPP\CppKalkulacky\platforms\qwindows.dll
2013-12-04 15:48 - 2014-02-01 16:39 - 00818176 _____ () C:\Program Files\Kooperativa\KoopPxBN\platforms\qwindows.dll
2015-03-23 13:13 - 2015-03-23 13:13 - 16858288 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows\System32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2850153352-4128204203-4000747475-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AdobeARMservice => 3
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: FLEXnet Licensing Service => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: KoopPdfService => 3
MSCONFIG\startupreg: BDRegion => C:\Program Files\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-2850153352-4128204203-4000747475-500 - Administrator - Disabled)
Guest (S-1-5-21-2850153352-4128204203-4000747475-501 - Limited - Disabled)
Jarda (S-1-5-21-2850153352-4128204203-4000747475-1000 - Administrator - Enabled) => C:\Users\Jarda
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Index nebyl inicializován.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Aplikace nebyla inicializována.
Kontext: aplikace Windows
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Objekt indexování nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Modul plug-in v <Search.TripoliIndexer> nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Prvek nebyl nalezen. (HRESULT : 0x80070490) (0x80070490)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Modul plug-in v <Search.JetPropStore> nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Služba Windows Search nenačetla informace o úložišti vlastností.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800) (0xc0041800)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4700} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: Služba Windows Search neotevřela úložiště vlastností databázového stroje Jet.
Podrobnosti:
0x%08x (0xc0041800 - Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800))
Error: (03/23/2015 08:57:45 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (3252) Windows: Při otevírání souboru protokolu C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS000D5.log došlo k chybě -1811.
System errors:
=============
Error: (03/23/2015 10:29:48 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:33:23 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:32:46 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 10.0.0.12192.168.137.0255.255.255.0
Error: (03/23/2015 09:05:33 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:01:52 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 10.0.0.12192.168.137.0255.255.255.0
Error: (03/23/2015 08:58:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba zařazování tisku neuspěla při spuštění v důsledku následující chyby:
%%1069
Error: (03/23/2015 08:58:13 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba Spooler se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50
Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).
Error: (03/23/2015 08:57:47 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 2 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (03/23/2015 08:57:47 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba Windows Search ukončena s chybou %%-1073473535, specifickou pro službu.
Error: (03/23/2015 08:57:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba zařazování tisku byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.
Microsoft Office Sessions:
=========================
Error: (06/23/2014 09:54:46 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 146 seconds with 120 seconds of active time. This session ended with a crash.
Error: (05/09/2014 07:29:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1911 seconds with 360 seconds of active time. This session ended with a crash.
Error: (01/03/2012 00:41:33 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash.
Error: (05/10/2010 10:21:22 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83602 seconds with 9000 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
Percentage of memory in use: 45%
Total physical RAM: 2038.4 MB
Available physical RAM: 1112.34 MB
Total Pagefile: 4076.8 MB
Available Pagefile: 3029.83 MB
Total Virtual: 2047.88 MB
Available Virtual: 1925.22 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:34.57 GB) (Free:7.15 GB) NTFS
Drive d: () (Fixed) (Total:112.92 GB) (Free:24.55 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 208E64FB)
Partition 1: (Not Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=34.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=112.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Tady je log z adcleaneru:
# AdwCleaner v4.113 - Logfile created 23/03/2015 at 20:56:28
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x86)
# Username : Jarda - JARDA-PC
# Running from : C:\Users\Jarda\Desktop\adwcleaner_4.113.exe
# Option : Cleaning
***** [ Services ] *****
[#] Service Deleted : Util neurowise
[#] Service Deleted : Update neurowise
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IHProtectUpDate
Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files\neurowise
Folder Deleted : C:\Users\Jarda\AppData\Local\genienext
Folder Deleted : C:\Users\Jarda\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Jarda\AppData\LocalLow\pdfforge
Folder Deleted : C:\Users\Jarda\AppData\LocalLow\Search Settings
Folder Deleted : C:\Users\Jarda\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Jarda\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Jarda\AppData\Roaming\RHEng
Folder Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\Extensions\anttoolbar@ant.com
File Deleted : C:\Users\Jarda\daemonprocess.txt
File Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\user.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{600C2A2B-3E71-43A3-8E0B-D0A64DA53249}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AAB3EF56-AA1D-4D75-A267-66355AB548B6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\pdfforge
Key Deleted : HKLM\SOFTWARE\Application Updater
Key Deleted : HKLM\SOFTWARE\pdfforge
Key Deleted : HKLM\SOFTWARE\Search Settings
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\IHProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.4 (x86 cs)
[ptwugzj4.default\prefs.js] - Line Deleted : user_pref("extensions.enabledItems", "pdfforge@mybrowserbar.com:1.1.2,searchsettings@spigot.com:1.2.3,{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18,{AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198,pi[...]
dostal se mi do rukou notebook, ktery byl radne zavirovany, prevazne v adresari appdata a pak jsem to projel jeste adwcleanerem a mbam, posledni jmenovany jiz nic nenasel. Ted k problemu, po tom vsem je ntb porad zpomaleny. Jiz jsem vypnul co se da po spusteni, probral sluzby, vycistil ccleanerem, zkontroloval disk jestli neni poskozeny a vypnul aero. Musi tam jeste nekde neco byt vnorene, jinak fakt uz nevim.
Tady je log z FRST:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Jarda at 2015-03-23 22:33:17
Running from C:\Users\Jarda\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.42.34 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
BatteryBar (remove only) (HKLM\...\BatteryBar) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
CyberLink PowerDVD 10 (HKLM\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.1705 - CyberLink Corp.)
CyberLink PowerDVD 10.0.1516.51 - odinstalovat češtinu (HKLM\...\CyberLink PowerDVD 10.0.1516.51) (Version: - Michellin & Pavlík)
ESET Smart Security (HKLM\...\{A68ED22D-17E8-4B1C-A32F-12177796BA61}) (Version: 8.0.304.1 - ESET, spol s r. o.)
Google Drive (HKLM\...\{6C36881B-0E51-4231-9D02-BF2149664D34}) (Version: 1.20.8672.3137 - Google, Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Java 7 Update 76 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217076FF}) (Version: 7.0.760 - Oracle)
KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 3.9.1.132 - PandoraTV)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
ModelPrint 1.0.52 (HKLM\...\ModelPrint 1.0.52) (Version: 1.0.52 - )
Mozilla Firefox 36.0.4 (x86 cs) (HKLM\...\Mozilla Firefox 36.0.4 (x86 cs)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML4 Parser (HKLM\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 0.9.9 - Frank Heindörfer, Philip Chinery)
pdfforge Toolbar v1.1.2 (HKLM\...\{5791B7D3-8B34-4218-9750-6A8E45D0AD32}) (Version: 1.1.2 - Spigot, Inc.) <==== ATTENTION
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
STORMWARE PDF Printer 10.1.0.1871 (HKLM\...\STORMWARE PDF Printer_is1) (Version: 10.1.0.1871 - STORMWARE)
STORMWARE POHODA CZ Standard MLP (HKLM\...\{21E61A26-B4FC-4366-B914-E1C67A505784}) (Version: 10800.192 - STORMWARE)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 7.50a - Ghisler Software GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN)
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{052253BF-F1FF-4686-B231-8D1904DEED68}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{0F81C552-68AD-4AAB-99D2-26F7F72A423C}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Commmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1B72D1C3-A1B3-4C87-9552-894CFF74051F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1BC0C7E7-0ADF-4FCE-9FBD-70B2DBC3BD48}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameMdl.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1E1C74D3-EF64-4F13-B631-DFDCEE4572FD}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Loginmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{1FD9E587-43E1-4F1F-A41F-A6E8B93A5546}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{2D0235FC-1701-4F1C-B36C-84CD8813EDB5}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{31DC369C-75C3-4D8B-9C2D-0B10BF77BA0F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{343ADE39-3C61-421B-93CB-19C44D33ED9B}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{47231DCA-F7A4-4696-B836-B2430D451226}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Imagemgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{4AC4E235-EB53-4942-B113-931D66A470B8}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameSelectorMdl.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{50021F2A-9C64-4766-A697-84E366A407B1}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{50632C37-EDD8-4B8F-A32B-8E280D942A8E}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{51B894AD-B2D5-48F6-B1D1-C1F0CF849587}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{553E32D1-AAF3-406A-B19E-E575829EC651}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{648326CD-6F37-4A8F-BF14-E2BAD67AAAA8}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{693566bc-21f8-401e-8d42-e2c5ce50dacc}\localserver32 -> C:\Users\Jarda\AppData\Local\Temp\{d5641912-e47a-429c-879e-cfe13eac7a13}\IDriver.NonElevated.exe No (the data entry has 4 more characters).
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{6BB1EAF0-7572-4166-9DF4-2A817F5FCD83}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{6F80F85C-FC5C-4C7E-B7ED-9ECCECC7CF57}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Configmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{72A62965-EF25-42E0-97CE-7A2D69BF28C0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8A0F754D-9636-4771-A1A6-8A1126E03345}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8A73CF97-446B-46AD-964C-2C3400CAA60F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8B48847D-052F-4153-93B8-7223BFF1C406}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Commmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{8B5F91E9-0032-4560-93B0-4539497C5366}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{941D2E9A-D724-4FB5-94D5-775B70E8C408}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{97637B78-01D0-4A40-A842-68774AA416BB}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{987585FA-DD0C-4E8B-8FC2-89B1181CA701}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{9A5A84A0-2E60-47D1-8C75-278A8D0F41FF}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{9E8F05AF-C18E-4A72-8743-A479EFD255E6}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A16CA865-CD74-46EC-9432-74579FD657A0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A2DF38B5-93D0-44D6-8130-AA80F351F852}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Timemgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A70E086C-1477-4B0C-808A-94EF8271ED39}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Resourcemgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{A7674421-DB75-4081-B0FE-2B378F1FFAEB}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\GameMdl.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ACAB158F-423F-4D59-BEDD-15C9E0CC2DD1}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B10A3751-CC13-4A25-875B-EEC84674C6C0}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Soundmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B1267A8A-D143-41F7-A655-5765A8464796}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B6C64A50-7BB8-441B-AE31-C4366C84BF00}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{B8217B92-8FDD-4A74-9417-B77BD74F62B7}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{BD75936F-2B69-477E-9E9A-218FFAF35F49}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{BE742811-02F4-4D7E-87C1-886909462A16}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Modulemgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D2E87C0B-C06A-4E69-8A41-0AC3117505B4}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D4A86438-A95B-487D-8B1D-1E67B2A0F379}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\DownloadMgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{D7B3EAC0-36D9-459E-AC96-3A88309FDDCC}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E65E6AAE-9169-4625-B98D-EB903E707116}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E6BFA606-59F2-4CD6-89C8-DAED6D789027}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{E9AC37A2-E79C-4CA3-A6A8-1884BF9A7852}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{EAD67B06-459C-48B9-90C1-5F2F34D4F83F}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ECA7C134-E84B-4E6B-A3E2-355FCB853766}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{ED0BD0F4-ECAC-41D2-BD28-0ABFB129F40C}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\VersionMgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{F0349E13-BD03-4073-BA25-6B2610C0750D}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{F53E4C9E-703C-41f3-8F69-C7E3D277594B}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{FD995983-DC2B-4B97-B3FE-E9534AA1A769}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Graphicsmgr.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-2850153352-4128204203-4000747475-1000_Classes\CLSID\{FE0AA82B-B32A-4D54-BA97-918D2A9F6E70}\InprocServer32 -> C:\Users\Jarda\AppData\Local\VTShared\Windowmgr.dll ()
==================== Restore Points =========================
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0149987B-2C2D-4941-848C-E999C7496C02} - System32\Tasks\{D5A08C13-DAF9-4305-A17F-1CC81566FEFC} => pcalua.exe -a G:\setup.exe -d G:\
Task: {03ED2C1B-E46E-4DE5-B1BD-61F97D352BA6} - System32\Tasks\{B69A4323-FD1D-4B76-8412-759752B923CC} => pcalua.exe -a G:\Installer.exe -d G:\
Task: {046A7CD2-2F9E-4595-B321-A65C03ACDE52} - System32\Tasks\{F6826F31-F3CC-4BD2-8FB9-98F054DCAFF9} => pcalua.exe -a "C:\Program Files\Common Files\CADS Shared\StructuralDesigners\SteelMemberDesigner\Uninstall SMD.exe" -c C:\Program Files\Common Files\CADS Shared\StructuralDesigners\SteelMemberDesigner\Install.log
Task: {0745BB18-569D-43FD-8243-6C9380AB0252} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: {0F025A5E-FA56-4BD1-A5DC-049A963E13BC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
Task: {0FA489BC-4407-49B5-953B-7AF80A0A3AB6} - System32\Tasks\{3151EBA5-BC2F-4EAE-BD04-E002892505D4} => C:\Program Files\Skype\Phone\Skype.exe
Task: {1123A1E1-A512-40F4-B438-284550483057} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-23] (Adobe Systems Incorporated)
Task: {18E4DCD7-61BC-4A86-927F-49F4C534D943} - System32\Tasks\{7C9A15EB-DDFE-4842-907B-E0811B66206D} => pcalua.exe -a D:\hry\steam\steam.exe -c steam://uninstall/34200
Task: {22C585C2-C4B2-42A3-B819-388C5CF0808E} - System32\Tasks\{1DD1D994-D800-4B08-9F53-A3C14D8C4136} => pcalua.exe -a C:\Users\Jarda\AppData\Roaming\webssearches\UninstallManager.exe -c -ptid=kmp <==== ATTENTION
Task: {2382DBB0-DF9F-434F-98EB-BC05AAE6E1FF} - System32\Tasks\{C068C1CF-590E-4CFF-99B8-4FE2237B7895} => pcalua.exe -a "D:\hry\Warcraft III\w3_battle124bfix2\w3_battle124bfix2.exe" -d "D:\hry\Warcraft III\w3_battle124bfix2"
Task: {39D2CC2A-653E-47A7-BF55-3F69388F9E02} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {3BBF137E-A8C3-4160-AF21-BD4AC4C06097} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {3DE5B956-522F-4F2D-ADCD-CDB8B0EF67D4} - System32\Tasks\{8E132A3C-514B-4098-8F65-900F6C109F7F} => Firefox.exe http://ui.skype.com/ui/0/6.0.0.126/cs/a ... rogressBar
Task: {5156D418-52AE-407D-94F4-61F2192EEA8F} - System32\Tasks\{7C74393A-60C9-43B2-9AEB-0861D91C2830} => pcalua.exe -a C:\Users\Jarda\Desktop\modem\Axesstel_Setup.exe -d C:\Users\Jarda\Desktop\modem
Task: {5AB1A5AE-012B-48CA-BF9A-D547623D4EDC} - System32\Tasks\{AAEAB2D3-9384-4D1A-A8B0-F05D5A11A446} => pcalua.exe -a D:\hry\w3_battle124bfix2\w3_battle124bfix2.exe -d D:\hry\w3_battle124bfix2
Task: {5DF48A6B-6E8D-4119-A20A-D266D35B6998} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-08] (Google Inc.)
Task: {5EDDAC18-82CF-437E-9D7B-1F2FD93D23AC} - System32\Tasks\{693BC7DC-C27F-4B3A-98AA-4942A618693F} => pcalua.exe -a "C:\Program Files\ModelPrint\1.0.52\uninstall.bat"
Task: {76DAE199-868B-41E2-ADE2-6BA4B788045E} - System32\Tasks\{FAEE0FF3-DD9B-42C2-B79B-6235F2329D60} => pcalua.exe -a G:\setup.exe -d G:\
Task: {771A4A4A-F53F-40C6-85A6-F622A8A19626} - System32\Tasks\{1C2E7BC4-24F7-4777-A1C6-4162AA6BE30A} => pcalua.exe -a F:\AUTORUN.EXE -d F:\
Task: {888BF0F9-B878-4D91-BB5B-839060BAFE52} - System32\Tasks\{8E20E725-3F61-4868-AD80-C85558789323} => pcalua.exe -a G:\setup.exe -d G:\
Task: {ACE47E23-1BA6-4CDF-A467-7635DA199FDE} - System32\Tasks\{18E89797-CAA7-43F9-81B6-B878762E0086} => pcalua.exe -a "C:\Program Files\InstallShield Installation Information\{6DBAF277-66A6-4DA9-8E01-AA549CED1DDB}\setup.exe" -c -runfromtemp -l0x0405 -removeonly
Task: {CD743E61-14B3-48CC-AD12-6D425F13D21C} - System32\Tasks\{307DDD9B-C03E-418E-AF28-245397E5F407} => pcalua.exe -a "C:\Program Files\AutoCAD 2010\Setup\Setup.exe" -c /P {5783F2D7-8001-0405-0002-0060B0CE6BBA} /M ACAD /language cs-CZ
Task: {CF4DF457-A4D7-4C22-92F7-1247BF8FFF7C} - System32\Tasks\{F2C1836E-D463-4432-AB93-5521B96CAF91} => pcalua.exe -a "D:\prace\škola\Projekt 1\Geo_5.exe" -d "D:\prace\škola\Projekt 1"
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2010-02-05 08:38 - 2001-10-28 16:42 - 00116224 _____ () C:\Windows\System32\pdfcmnnt.dll
2010-02-04 07:41 - 2008-08-29 10:55 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll
2010-02-04 07:41 - 2008-09-03 15:28 - 00319488 _____ () C:\Program Files\WinRAR\rarlng.dll
2014-03-23 23:29 - 2014-03-23 23:29 - 00818176 _____ () C:\CPP\CppKalkulacky\platforms\qwindows.dll
2013-12-04 15:48 - 2014-02-01 16:39 - 00818176 _____ () C:\Program Files\Kooperativa\KoopPxBN\platforms\qwindows.dll
2015-03-23 13:13 - 2015-03-23 13:13 - 16858288 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows\System32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57}
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2850153352-4128204203-4000747475-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AdobeARMservice => 3
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: FLEXnet Licensing Service => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: KoopPdfService => 3
MSCONFIG\startupreg: BDRegion => C:\Program Files\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-2850153352-4128204203-4000747475-500 - Administrator - Disabled)
Guest (S-1-5-21-2850153352-4128204203-4000747475-501 - Limited - Disabled)
Jarda (S-1-5-21-2850153352-4128204203-4000747475-1000 - Administrator - Enabled) => C:\Users\Jarda
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Index nebyl inicializován.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Aplikace nebyla inicializována.
Kontext: aplikace Windows
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Objekt indexování nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:47 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Modul plug-in v <Search.TripoliIndexer> nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Prvek nebyl nalezen. (HRESULT : 0x80070490) (0x80070490)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Modul plug-in v <Search.JetPropStore> nebyl inicializován.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: Služba Windows Search nenačetla informace o úložišti vlastností.
Kontext: aplikace Windows, katalog SystemIndex
Podrobnosti:
Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800) (0xc0041800)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4700} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.
Podrobnosti:
Katalog indexu obsahu je poškozený. (HRESULT : 0xc0041801) (0xc0041801)
Error: (03/23/2015 08:57:46 PM) (Source: Windows Search Service) (EventID: 9000) (User: )
Description: Služba Windows Search neotevřela úložiště vlastností databázového stroje Jet.
Podrobnosti:
0x%08x (0xc0041800 - Databáze indexu obsahu je poškozená. (HRESULT : 0xc0041800))
Error: (03/23/2015 08:57:45 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Windows (3252) Windows: Při otevírání souboru protokolu C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS000D5.log došlo k chybě -1811.
System errors:
=============
Error: (03/23/2015 10:29:48 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:33:23 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:32:46 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 10.0.0.12192.168.137.0255.255.255.0
Error: (03/23/2015 09:05:33 PM) (Source: ipnathlp) (EventID: 31004) (User: )
Description: 0
Error: (03/23/2015 09:01:52 PM) (Source: ipnathlp) (EventID: 30013) (User: )
Description: 10.0.0.12192.168.137.0255.255.255.0
Error: (03/23/2015 08:58:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba zařazování tisku neuspěla při spuštění v důsledku následující chyby:
%%1069
Error: (03/23/2015 08:58:13 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba Spooler se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%50
Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).
Error: (03/23/2015 08:57:47 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 2 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (03/23/2015 08:57:47 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Služba Windows Search ukončena s chybou %%-1073473535, specifickou pro službu.
Error: (03/23/2015 08:57:13 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba zařazování tisku byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 60000 milisekund: Restartovat službu.
Microsoft Office Sessions:
=========================
Error: (06/23/2014 09:54:46 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 146 seconds with 120 seconds of active time. This session ended with a crash.
Error: (05/09/2014 07:29:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 1911 seconds with 360 seconds of active time. This session ended with a crash.
Error: (01/03/2012 00:41:33 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash.
Error: (05/10/2010 10:21:22 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83602 seconds with 9000 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
Percentage of memory in use: 45%
Total physical RAM: 2038.4 MB
Available physical RAM: 1112.34 MB
Total Pagefile: 4076.8 MB
Available Pagefile: 3029.83 MB
Total Virtual: 2047.88 MB
Available Virtual: 1925.22 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:34.57 GB) (Free:7.15 GB) NTFS
Drive d: () (Fixed) (Total:112.92 GB) (Free:24.55 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 208E64FB)
Partition 1: (Not Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=34.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=112.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Tady je log z adcleaneru:
# AdwCleaner v4.113 - Logfile created 23/03/2015 at 20:56:28
# Updated 22/03/2015 by Xplode
# Database : 2015-03-23.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x86)
# Username : Jarda - JARDA-PC
# Running from : C:\Users\Jarda\Desktop\adwcleaner_4.113.exe
# Option : Cleaning
***** [ Services ] *****
[#] Service Deleted : Util neurowise
[#] Service Deleted : Update neurowise
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\IHProtectUpDate
Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files\neurowise
Folder Deleted : C:\Users\Jarda\AppData\Local\genienext
Folder Deleted : C:\Users\Jarda\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Jarda\AppData\LocalLow\pdfforge
Folder Deleted : C:\Users\Jarda\AppData\LocalLow\Search Settings
Folder Deleted : C:\Users\Jarda\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Jarda\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Jarda\AppData\Roaming\RHEng
Folder Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\Extensions\anttoolbar@ant.com
File Deleted : C:\Users\Jarda\daemonprocess.txt
File Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\searchplugins\daemon-search.xml
File Deleted : C:\Users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\ptwugzj4.default\user.js
***** [ Scheduled tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{600C2A2B-3E71-43A3-8E0B-D0A64DA53249}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AAB3EF56-AA1D-4D75-A267-66355AB548B6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\pdfforge
Key Deleted : HKLM\SOFTWARE\Application Updater
Key Deleted : HKLM\SOFTWARE\pdfforge
Key Deleted : HKLM\SOFTWARE\Search Settings
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\IHProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
***** [ Web browsers ] *****
-\\ Internet Explorer v11.0.9600.17689
-\\ Mozilla Firefox v36.0.4 (x86 cs)
[ptwugzj4.default\prefs.js] - Line Deleted : user_pref("extensions.enabledItems", "pdfforge@mybrowserbar.com:1.1.2,searchsettings@spigot.com:1.2.3,{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18,{AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198,pi[...]